ZeroHour

CVE-2021-24510

CVSS 3.1
6.1 medium
EPSS
3%p85
Published
()
Modified
Description

The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter before outputting back in the admin dashboard when editing an Event, leading to a reflected Cross-Site Scripting issue

Vendors
mf gig calendar project
Products
mf gig calendar
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.