CVE-2021-24214
OpenID Connect Generic Client 3.8.0-3.8.1 - Reflected Cross Site Scripting (XSS) via Login Error
The OpenID Connect Generic Client WordPress plugin 3.8.0 and 3.8.1 did not sanitise the login error when output back in the login form, leading to a reflected Cross-Site Scripting issue. This issue does not require authentication and can be exploited with the default configuration.
Produtos afetados
daggerhart · OpenID Connect Generic ClientQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →