Lucene search

K
cvelistWordfenceCVELIST:CVE-2021-39322
HistorySep 02, 2021 - 4:42 p.m.

CVE-2021-39322 Easy Social Icons <= 3.0.8 - Reflected Cross-Site Scripting

2021-09-0216:42:38
CWE-79
Wordfence
www.cve.org
3
cve-2021-39322
easy social icons
3.0.8
reflected cross-site scripting
wordpress
apache
modphp

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.003

Percentile

65.9%

The Easy Social Icons plugin <= 3.0.8 for WordPress echoes out the raw value of $_SERVER['PHP_SELF'] in its main file. On certain configurations including Apache+modPHP this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path.

CNA Affected

[
  {
    "product": "Easy Social Icons",
    "vendor": "cybernetikz",
    "versions": [
      {
        "lessThanOrEqual": "3.0.8",
        "status": "affected",
        "version": "3.0.8",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.003

Percentile

65.9%