CVE Database
/

CVE-2021-24177

Back to search

CVE-2021-24177

Published: Apr 5, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response.

VendorProductVersions

Unknown

File Manager

affected
7.1 - < 7.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now