Lucene search

K
cvelistWPScanCVELIST:CVE-2021-24874
HistoryFeb 14, 2022 - 9:20 a.m.

CVE-2021-24874 Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue < 3.1.31 - Reflected Cross-Site Scripting

2022-02-1409:20:36
CWE-79
WPScan
www.cve.org
1

0.001 Low

EPSS

Percentile

40.2%

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

CNA Affected

[
  {
    "product": "Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "3.1.31",
        "status": "affected",
        "version": "3.1.31",
        "versionType": "custom"
      }
    ]
  }
]

0.001 Low

EPSS

Percentile

40.2%