CVE-2021-24508: fallo en Smash Balloon Social Post Feed
Smash Balloon Social Post Feed < 2.19.2 - Unauthenticated Stored XSS
Publicada el · Actualizada el
3Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 1.3%
probabilidad de explotación
1.3%top 30% de las CVE
explotación observada
noninguna fuente lo reporta
The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it in the admin dashboard, leading to an unauthenticated Stored Cross-Site Scripting issue which will be executed in the context of a logged in administrator.
Productos afectados
Unknown · Smash Balloon Social Post FeedCVEs relacionadas — Smash Balloon Social Post Feed
En el mismo producto, de las más peligrosas a las menos.
CVE-2021-25065—Smash Balloon Social Post Feed < 4.1.1 - Authenticated Reflected Cross-Site Scripting (XSS)EPSS 1.0%CVE-2021-24918—Smash Balloon Social Post Feed < 4.0.1 - Subscriber+ Arbitrary Plugin Settings Update to Stored XSSEPSS 0.7%CVE-2022-4477MEDIUMSmash Balloon Social Post Feed < 4.1.6 - Contributor+ Stored XSSEPSS 0.5%