Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inject arbitrary JavaScript code or HTML without approval. This could lead to privilege escalation
                
            References
                    | Link | Resource | 
|---|---|
| https://mega.nz/file/ftVSmRCC#ctqUg89CKszEuLO3eeQVazUStTPvoQD6LlbWNSMa7uA | Exploit Third Party Advisory | 
| https://wpscan.com/vulnerability/8b6f4a77-4008-4730-9a91-fa055a8b3e68 | Exploit Third Party Advisory | 
| https://mega.nz/file/ftVSmRCC#ctqUg89CKszEuLO3eeQVazUStTPvoQD6LlbWNSMa7uA | Exploit Third Party Advisory | 
| https://wpscan.com/vulnerability/8b6f4a77-4008-4730-9a91-fa055a8b3e68 | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 05:52
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://mega.nz/file/ftVSmRCC#ctqUg89CKszEuLO3eeQVazUStTPvoQD6LlbWNSMa7uA - Exploit, Third Party Advisory | |
| References | () https://wpscan.com/vulnerability/8b6f4a77-4008-4730-9a91-fa055a8b3e68 - Exploit, Third Party Advisory | 
Information
                Published : 2021-04-05 19:15
Updated : 2024-11-21 05:52
NVD link : CVE-2021-24156
Mitre link : CVE-2021-24156
CVE.ORG link : CVE-2021-24156
JSON object : View
Products Affected
                testimonial_rotator_project
- testimonial_rotator
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
