PT-2021-4128 · WordPress · Simple Behance Portfolio
P7E4
·
Published
2021-08-16
·
Updated
2021-08-23
·
CVE-2021-34649
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Simple Behance Portfolio WordPress plugin versions up to and including 0.2
Description
The issue allows attackers to inject arbitrary web scripts via the
dark parameter in the ~/titan-framework/iframe-font-preview.php file. This is a Reflected Cross-Site Scripting vulnerability.Recommendations
For versions up to and including 0.2, consider disabling access to the ~/titan-framework/iframe-font-preview.php file or restricting the use of the
dark parameter until a patch is available.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple Behance Portfolio