Ivory Search < 4.6.1 - Reflected Cross Site Scripting (XSS)
CVE-2021-24234

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
22 April 2021

Summary

The Search Forms page of the Ivory Search WordPress lugin before 4.6.1 did not properly sanitise the tab parameter before output it in the page, leading to a reflected Cross-Site Scripting issue when opening a malicious crafted link as a high privilege user. Knowledge of a form id is required to conduct the attack.

Affected Version(s)

Ivory Search – WordPress Search Plugin 4.6.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jinson Varghese Behanan
.