🔙 목록으로 돌아가기

CVE-2021-24176: WordPress JH 404 Logger <=1.1 - Cross-Site Scripting

TitleWordPress JH 404 Logger <=1.1 - Cross-Site Scripting
AuthorGanofins
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to potential data theft or unauthorized actions.
RemediationUpdate to the latest version of WordPress JH 404 Logger plugin (>=1.2) which addresses the XSS vulnerability.
CVSS Score5.4
EPSS Score0.21335
CVE IDCVE-2021-24176
CWE IDCWE-79
Tags cve2021 cve wordpress wp-plugin xss wpscan jh_404_logger_project vuln

🔍 Vulnerability Description

WordPress JH 404 Logger plugin through 1.1 contains a cross-site scripting vulnerability. Referer and path of 404 pages are not properly sanitized when they are output in the WordPress dashboard, which can lead to executing arbitrary JavaScript code.

🌐 HTTP Request

GET /wp-content/plugins/jh-404-logger/readme.txt HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; WOW64; rv:41.0) Gecko/20100101 Firefox/140.0.4 (x64 de)
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24176.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-24176.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A