PT-2021-15992 · WordPress · Leaflet Map
Apple502J
·
Published
2021-08-09
·
Updated
2023-02-03
·
CVE-2021-24467
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Leaflet Map WordPress plugin versions prior to 3.0.0
Description
The issue allows attackers to make a logged-in admin update the plugin's settings via a Cross-Site Request Forgery attack because it does not verify the CSRF nonce when saving its settings. This could lead to Cross-Site Scripting issues by either changing the URL of the JavaScript library being used or using malicious attributions that will be executed in all pages with an embedded map from the plugin.
Recommendations
For versions prior to 3.0.0, update to version 3.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's settings page to minimize the risk of exploitation. Avoid using malicious attributions in the plugin's settings until the issue is resolved.
Exploit
Fix
XSS
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Leaflet Map