The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events before outputting them in the Orders admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2021-12-27T10:33:19

Updated: 2024-08-03T19:42:17.174Z

Reserved: 2021-01-14T00:00:00

Link: CVE-2021-24797

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-27T11:15:08.673

Modified: 2024-11-21T05:53:46.977

Link: CVE-2021-24797

cve-icon Redhat

No data.