Description
The My Tickets WordPress plugin before 1.8.31 does not properly sanitise and escape the Email field of booked tickets before outputting it in the Payment admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins
Published: 2021-11-17
Score: 6.1 Medium
EPSS: 12.1% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

My Tickets Project My Tickets
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-03T19:42:17.335Z

Reserved: 2021-01-14T00:00:00.000Z

Link: CVE-2021-24796

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-11-17T11:15:07.853

Modified: 2024-11-21T05:53:46.863

Link: CVE-2021-24796

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses