.. / CVE-2021-25078

Exploit for Affiliates Manager < 2.9.0 - Cross Site Scripting (CVE-2021-25078)

Description:

The plugin does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests.

Nuclei Template

View the template here CVE-2021-25078.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-25078.yaml
Copy

References:

https://wpscan.com/vulnerability/d4edb5f2-aa1b-4e2d-abb4-76c46def6c6e
https://github.com/ARPSyndicate/cvemon
https://plugins.trac.wordpress.org/changeset/2648196
https://nvd.nist.gov/vuln/detail/CVE-2021-25078