PT-2021-16055 · WordPress · Phonetrack Meu Site Manager

Abisheik M

·

Published

2021-08-16

·

Updated

2021-08-23

·

CVE-2021-24534

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PhoneTrack Meu Site Manager WordPress plugin version 0.1
Description The issue arises from the plugin not sanitising or escaping its php id setting before outputting it back in an attribute in the page, leading to a stored Cross-Site Scripting issue.
Recommendations For version 0.1, consider disabling the output of the php id setting in the page attribute until a patch is available to prevent exploitation of the stored Cross-Site Scripting issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24534

Affected Products

Phonetrack Meu Site Manager