PT-2021-15992 · WordPress · Leaflet Map

Apple502J

·

Published

2021-08-09

·

Updated

2023-02-03

·

CVE-2021-24467

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Leaflet Map WordPress plugin versions prior to 3.0.0
Description The issue allows attackers to make a logged-in admin update the plugin's settings via a Cross-Site Request Forgery attack because it does not verify the CSRF nonce when saving its settings. This could lead to Cross-Site Scripting issues by either changing the URL of the JavaScript library being used or using malicious attributions that will be executed in all pages with an embedded map from the plugin.
Recommendations For versions prior to 3.0.0, update to version 3.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's settings page to minimize the risk of exploitation. Avoid using malicious attributions in the plugin's settings until the issue is resolved.

Exploit

Fix

XSS

CSRF

Weakness Enumeration

Related Identifiers

CVE-2021-24467

Affected Products

Leaflet Map