giveasap是一款WordPress插件 GIVEASAP存在安全漏洞,该漏洞源于share GET参数没有经过消毒、验证或转义,因此导致了反射XSS。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Igor Benic | Simple Giveaways – Grow your business, email lists and traffic with contests | 2.36.2 ~ 2.36.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WordPress Simple Giveaways plugin before 2.36.2 contains a cross-site scripting vulnerability via the method and share GET parameters of the Giveaway pages, which are not sanitized, validated, or escaped before being output back in the pages. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24298.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet