CVE-2021-24794: Connections Business Directory < 10.4.3 - Admin+ Stored Cross-Site Scripting
Published Nov 1, 2021
·Updated
The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an Entry, which could allow high privilege users to perform Cross-Site Scripting when the unfilteredhtml capability is disallowed.
Affected Software
1 affected component
Connections-pro Connections Business Directory Wordpress<10.4.3
Event History
Nov 1, 2021
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24794?
CVE-2021-24794 is considered a high severity vulnerability due to its potential for Cross-Site Scripting attacks.
2
How do I fix CVE-2021-24794?
To fix CVE-2021-24794, update the Connections Business Directory plugin to version 10.4.3 or later.
3
Who is affected by CVE-2021-24794?
CVE-2021-24794 affects users of the Connections Business Directory plugin prior to version 10.4.3.
4
What type of vulnerability is CVE-2021-24794?
CVE-2021-24794 is a Cross-Site Scripting (XSS) vulnerability.
5
Can low privilege users exploit CVE-2021-24794?
No, only high privilege users can exploit CVE-2021-24794 when the unfiltered_html capability is disallowed.