The My Tickets WordPress plugin... CVE-2021-24796

4.3 AV AC AU C I A
发布: 2021-11-17
修订: 2024-11-21

The My Tickets WordPress plugin before 1.8.31 does not properly sanitise and escape the Email field of booked tickets before outputting it in the Payment admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins

0%
暂无可用Exp或PoC
当前有1条受影响产品信息