ZeroHour

CVE-2021-24794

PoC
CVSS 3.1
4.8 medium
EPSS
<1%p52
Published
()
Modified
Description

The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an Entry, which could allow high privilege users to perform Cross-Site Scripting when the unfiltered_html capability is disallowed.

Vendors
connections-pro
Products
connections business directory
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.