// For flags

CVE-2021-24408

Prismatic < 2.8 - Contributor+ Stored XSS

Severity Score

5.4
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Prismatic WordPress plugin before 2.8 does not sanitise or validate some of its shortcode parameters, allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an admin to have the XSS trigger able in the frontend, however, higher privilege users, such as editor could exploit this without the need of approval, and even when the blog disallows the unfiltered_html capability.

El plugin Prismatic de WordPress versiones anteriores a 2.8, no sanea o comprueba algunos de sus parámetros shortcode, permitiendo a usuarios con un rol tan bajo como el de colaborador ajustar carga útil de tipo Cross-Site en ellos. Un post hecho por un colaborador todavía tendría que ser aprobado por un administrador para que el ataque XSS se desencadene en el frontend, sin embargo, los usuarios con mayores privilegios, como el editor podrían explotar esto sin necesidad de aprobación, e incluso cuando el blog deshabilita la capacidad unfiltered_html

*Credits: apple502j
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-01-14 CVE Reserved
  • 2021-06-21 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Plugin-planet
Search vendor "Plugin-planet"
Prismatic
Search vendor "Plugin-planet" for product "Prismatic"
< 2.8
Search vendor "Plugin-planet" for product "Prismatic" and version " < 2.8"
wordpress
Affected