CVE-2021-24409: Prismatic < 2.8 - Reflected Cross-Site Scripting (XSS)
Published Jul 12, 2021
·Updated
The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator
Affected Software
1 affected component
Plugin-planet Prismatic Wordpress<2.8
Event History
Jul 12, 2021
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-24409.
2
What is the severity of CVE-2021-24409?
CVE-2021-24409 has a severity value of 6.1 (medium).
3
What software is affected by CVE-2021-24409?
The Prismatic WordPress plugin versions up to and excluding 2.8 are affected by CVE-2021-24409.
4
What is the impact of CVE-2021-24409?
CVE-2021-24409 can lead to a reflected Cross-Site Scripting (XSS) issue executed in the context of a logged-in administrator.
5
Is there a fix available for CVE-2021-24409?
To mitigate CVE-2021-24409, it is recommended to update the Prismatic WordPress plugin to version 2.8 or higher.