CVE-2021-24443
Youzify < 1.0.7 - Stored Cross-Site Scripting via Biography
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin before 1.0.7 does not properly sanitise its Biography field, allowing any authenticated user to set Cross-Site Scripting payloads in it, which will be executed when viewing the affected user profile. This could allow a low privilege user to gain unauthorised access to the admin side of the blog by targeting an admin, inducing them to view their profile with a malicious payload adding a rogue account for example.
Los plugins About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership de Wordpress versiones anteriores a 1.0.7, no sanea apropiadamente su campo Biography, permitiendo a cualquier usuario autenticado ajustar cargas útiles de tipo Cross-Site Scripting en él, que se ejecutarán cuando se visualice el perfil del usuario afectado. Esto podría permitir a un usuario con pocos privilegios obtener acceso no autorizado a la parte de administración del blog apuntando a un administrador, induciéndole a ver su perfil con una carga útil maliciosa añadiendo una cuenta falsa, por ejemplo
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-14 CVE Reserved
- 2021-06-28 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/a4432acd-df49-4a4f-8184-b55cdd5d4d34 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kainelabs Search vendor "Kainelabs" | Youzify Search vendor "Kainelabs" for product "Youzify" | < 1.0.7 Search vendor "Kainelabs" for product "Youzify" and version " < 1.0.7" | wordpress |
Affected
|