Lucene search

K
cvelistWPScanCVELIST:CVE-2021-24388
HistoryJul 06, 2021 - 11:03 a.m.

CVE-2021-24388 Vik Rent Car < 1.1.7 - CSRF to Stored XSS

2021-07-0611:03:29
CWE-352
CWE-79
WPScan
www.cve.org

0.001 Low

EPSS

Percentile

21.2%

In the VikRentCar Car Rental Management System WordPress plugin before 1.1.7, there is a custom filed option by which we can manage all the fields that the users will have to fill in before saving the order. However, the field name is not sanitised or escaped before being output back in the page, leading to a stored Cross-Site Scripting issue. There is also no CSRF check done before saving the setting, allowing attackers to make a logged in admin set arbitrary Custom Fields, including one with XSS payload in it.

CNA Affected

[
  {
    "product": "VikRentCar Car Rental Management System",
    "vendor": "E4J s.r.l.",
    "versions": [
      {
        "lessThan": "1.1.7",
        "status": "affected",
        "version": "1.1.7",
        "versionType": "custom"
      }
    ]
  }
]

0.001 Low

EPSS

Percentile

21.2%

Related for CVELIST:CVE-2021-24388