The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events before outputting them in the Orders admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2021-12-27T10:33:19

Updated: 2021-12-27T10:33:19

Reserved: 2021-01-14T00:00:00


Link: CVE-2021-24797

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-12-27T11:15:08.673

Modified: 2022-01-06T17:42:03.793


Link: CVE-2021-24797

JSON object: View

cve-icon Redhat Information

No data.

CWE