The Workscout Core WordPress plugin before 1.3.4, used by the WorkScout Theme did not sanitise the chat messages sent via the workscout_send_message_chat AJAX action, leading to Stored Cross-Site Scripting and Cross-Frame Scripting issues
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2021-05-06 13:15
Updated : 2023-11-07 03:31
NVD link : CVE-2021-24246
Mitre link : CVE-2021-24246
CVE.ORG link : CVE-2021-24246
JSON object : View
Products Affected
purethemes
- workscout_core
- workscout
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')