The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2021-05-24T10:58:04
Updated: 2024-08-03T19:28:23.261Z
Reserved: 2021-01-14T00:00:00
Link: CVE-2021-24298
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-05-24T11:15:08.143
Modified: 2024-11-21T05:52:47.430
Link: CVE-2021-24298
Redhat
No data.