PT-2021-21380 · Yith · Yith Maintenance Mode

Re-Alter

+1

·

Published

2021-09-27

·

Updated

2021-10-12

·

CVE-2021-36845

CVSS v3.1

6.9

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions YITH Maintenance Mode versions <= 1.3.8
Description Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities exist in the YITH Maintenance Mode WordPress plugin. There are 46 vulnerable parameters that were missed by the vendor while patching version 1.3.7 to 1.3.8. Vulnerable parameters include those in the "Newsletter", "General", "Background", "Logo", and "Socials" tabs. For example, the yith maintenance newsletter submit label parameter is vulnerable to XSS attacks, where a payload starting with a single quote symbol can break the context and trigger an alert when an admin visits the page.
Recommendations To resolve the issue for versions <= 1.3.8, update to a version greater than 1.3.8. As a temporary workaround, consider disabling the vulnerable parameters, such as yith maintenance newsletter submit label, yith maintenance message, yith maintenance custom style, and others, until a patch is available. Restrict access to the vulnerable tabs, including "Newsletter", "General", "Background", "Logo", and "Socials", to minimize the risk of exploitation. Avoid using the vulnerable parameters in the affected API endpoints until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36845

Affected Products

Yith Maintenance Mode