The My Tickets WordPress plugin before 1.8.31 does not properly sanitise and escape the Email field of booked tickets before outputting it in the Payment admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2021-11-17T10:15:40

Updated: 2024-08-03T19:42:17.335Z

Reserved: 2021-01-14T00:00:00

Link: CVE-2021-24796

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-11-17T11:15:07.853

Modified: 2024-11-21T05:53:46.863

Link: CVE-2021-24796

cve-icon Redhat

No data.