Vulnerabilities > CVE-2021-24479 - Unspecified vulnerability in Drawblog Project Drawblog 0.90

047910
CVSS 4.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
drawblog-project

Summary

The DrawBlog WordPress plugin through 0.90 does not sanitise or validate some of its settings before outputting them back in the page, leading to an authenticated stored Cross-Site Scripting issue

Vulnerable Configurations

Part Description Count
Application
Drawblog_Project
2