CVE-2021-24335: Car Repair Services < 4.0 - Unauthenticated Reflected XSS & XFS
The Car Repair Services & Auto Mechanic WordPress theme before 4.0 did not properly sanitise its serviceestimatekey search parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting issue
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24335?
CVE-2021-24335 is classified as a medium severity vulnerability due to its potential for reflected Cross-Site Scripting attacks.
How do I fix CVE-2021-24335?
To fix CVE-2021-24335, update the Car Repair Services & Auto Mechanic WordPress theme to version 4.0 or later.
What systems are affected by CVE-2021-24335?
CVE-2021-24335 affects versions of the Car Repair Services & Auto Mechanic WordPress theme prior to version 4.0.
What type of vulnerability is CVE-2021-24335?
CVE-2021-24335 is a reflected Cross-Site Scripting vulnerability that arises from improper sanitization of user input.
Can CVE-2021-24335 be exploited remotely?
Yes, CVE-2021-24335 can be exploited remotely by an attacker through a crafted request to the vulnerable theme.