CVE-2021-42365: Asgaros Forums <= 1.15.13 Authenticated Stored XSS
The Asgaros Forums WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the name parameter found in the ~/admin/tables/admin-structure-table.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.15.13. This affects multi-site installations where unfilteredhtml is disabled for administrators, and sites where unfilteredhtml is disabled.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this Asgaros Forums WordPress plugin vulnerability?
The vulnerability ID for this Asgaros Forums WordPress plugin vulnerability is CVE-2021-42365.
What is the severity level of CVE-2021-42365?
The severity level of CVE-2021-42365 is medium, with a severity value of 4.8.
What is the affected software for CVE-2021-42365?
The affected software for CVE-2021-42365 is the Asgaros Forums WordPress plugin up to version 1.15.14.
How does the vulnerability occur in the Asgaros Forums WordPress plugin?
The vulnerability occurs due to insufficient escaping via the name parameter found in the ~/admin/tables/admin-structure-table.php file of the Asgaros Forums WordPress plugin.
How can attackers exploit this vulnerability?
Attackers with administrative user access can exploit this vulnerability by injecting arbitrary web scripts.