Back to search
CVE-2021-24437
Published: Aug 30, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting (XSS) which is executed in the context of a logged administrator.
| Vendor | Product | Versions |
|---|---|---|
Unknown | Favicon by RealFaviconGenerator | affected 1.3.20 - <= 1.3.20 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now