CVE-2021-24365

The Admin Columns WordPress plugin Free before 4.3.2 and Pro before 5.5.2 allowed to configure individual columns for tables. Each column had a type. The type "Custom Field" allowed to choose an arbitrary database column to display in the table. There was no escaping applied to the contents of "Custom Field" columns.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:admincolumns:admin_columns:*:*:*:*:free:wordpress:*:*
cpe:2.3:a:admincolumns:admin_columns:*:*:*:*:pro:wordpress:*:*

Information

Published : 2021-07-12 13:15

Updated : 2021-07-15 07:29


NVD link : CVE-2021-24365

Mitre link : CVE-2021-24365


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

admincolumns

  • admin_columns