CVE-2021-24156

Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inject arbitrary JavaScript code or HTML without approval. This could lead to privilege escalation
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:testimonial_rotator_project:testimonial_rotator:3.0.3:*:*:*:*:wordpress:*:*

Information

Published : 2021-04-05 12:15

Updated : 2021-04-08 12:22


NVD link : CVE-2021-24156

Mitre link : CVE-2021-24156


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

testimonial_rotator_project

  • testimonial_rotator