CVE-2021-24407: Jannah < 5.4.5 - Reflected Cross-Site Scripting (XSS)
Published Jul 6, 2021
·Updated
The Jannah WordPress theme before 5.4.5 did not properly sanitize the 'query' POST parameter in its tieajaxsearch AJAX action, leading to a Reflected Cross-site Scripting (XSS) vulnerability.
Affected Software
1 affected component
Tielabs Jannah Wordpress<5.4.5
Event History
Jul 6, 2021
CVE Published
via MITRE·11:03 AM
Data Sourced
via MITRE·11:03 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
CVE-2021-24407
2
What is the severity of CVE-2021-24407?
Medium (6.1)
3
What is the affected software?
The Jannah WordPress theme before version 5.4.5.
4
What is the description of CVE-2021-24407?
The Jannah WordPress theme did not properly sanitize the 'query' parameter, leading to a Reflected Cross-site Scripting (XSS) vulnerability.
5
How can I fix CVE-2021-24407?
Update to version 5.4.5 of the Jannah WordPress theme.