PT-2021-16227 · Motopress · Timetable/Event Schedule
Martin Vierula
·
Published
2021-09-13
·
Updated
2021-09-23
·
CVE-2021-24724
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Timetable and Event Schedule by MotoPress WordPress plugin versions prior to 2.3.19
Description
The issue allows low privilege users, such as authors, to perform XSS attacks against frontend and backend users when viewing related events. This is due to the plugin not sanitizing some of its parameters.
Recommendations
For versions prior to 2.3.19, update to version 2.3.19 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's functionality for low-privilege users until the update is applied.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Timetable/Event Schedule