The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, which could allow low privilege users such as author to perform XSS attacks against frontend and backend users when viewing the related event/s
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2021-09-13T17:56:38
Updated: 2024-08-03T19:42:16.651Z
Reserved: 2021-01-14T00:00:00
Link: CVE-2021-24724
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-09-13T18:15:18.243
Modified: 2024-11-21T05:53:38.293
Link: CVE-2021-24724
Redhat
No data.