CVE Feed

    Dashboard / CVE / CVE-2021-24581

    CVE-2021-24581

    The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its settings, allowing the issue to be exploited via a CSRF attack.

    Published:Aug 30, 2021
    Last Modified:Nov 21, 2024
    EPS:Aug 30, 2021
    EPSS Score:0.0393
    CVSS Score:8.8

    Affected Products

    Vendor
    Blue-admin Project
    Product
    Blue-admin

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High