CVE Database
/

CVE-2021-24237

Back to search

CVE-2021-24237

Published: Apr 22, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not properly sanitise the keyword_search, search_radius. _bedrooms and _bathrooms GET parameters before outputting them in its properties page, leading to an unauthenticated reflected Cross-Site Scripting issue.

VendorProductVersions

PureThemes

Realteo

affected
1.2.4 - < 1.2.4

PureThemes

Findeo

affected
1.3.1 - < 1.3.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now