Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-24298 PoC — giveasap 跨站脚本漏洞

Source
Associated Vulnerability
Title:giveasap 跨站脚本漏洞 (CVE-2021-24298)
Description:giveasap是一款WordPress插件 GIVEASAP存在安全漏洞,该漏洞源于share GET参数没有经过消毒、验证或转义,因此导致了反射XSS。
Description
WordPress Simple Giveaways plugin before 2.36.2 contains a cross-site scripting vulnerability via the method and share GET parameters of the Giveaway pages, which are not sanitized, validated, or escaped before being output back in the pages.
File Snapshot

id: CVE-2021-24298 info: name: WordPress Simple Giveaways <2.36.2 - Cross-Site Scripting author ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.