Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post. There were no checks to verify that a user had the unfiltered_html capability prior to saving the script tags, thus allowing lower-level users to inject scripts that could potentially be malicious.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-11071 Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post. There were no checks to verify that a user had the unfiltered_html capability prior to saving the script tags, thus allowing lower-level users to inject scripts that could potentially be malicious.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-03T19:21:18.299Z

Reserved: 2021-01-14T00:00:00

Link: CVE-2021-24157

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-05T19:15:14.873

Modified: 2024-11-21T05:52:29.293

Link: CVE-2021-24157

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses