Vulnerabilities > CVE-2021-24234 - Unspecified vulnerability in Ivorysearch Ivory Search
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
The Search Forms page of the Ivory Search WordPress lugin before 4.6.1 did not properly sanitise the tab parameter before output it in the page, leading to a reflected Cross-Site Scripting issue when opening a malicious crafted link as a high privilege user. Knowledge of a form id is required to conduct the attack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 9 |
References
- https://wpscan.com/vulnerability/ecc620be-8e29-4860-9d32-86b5814a3835
- https://wpscan.com/vulnerability/ecc620be-8e29-4860-9d32-86b5814a3835
- https://www.getastra.com/blog/911/plugin-exploit/reflected-xss-vulnerability-in-ivory-search-wp-plugin/
- https://www.getastra.com/blog/911/plugin-exploit/reflected-xss-vulnerability-in-ivory-search-wp-plugin/
- https://www.jinsonvarghese.com/reflected-xss-vulnerability-found-in-ivory-search-plugin/
- https://www.jinsonvarghese.com/reflected-xss-vulnerability-found-in-ivory-search-plugin/