Vulnerabilities > CVE-2021-34650 - Unspecified vulnerability in Eideasy EID Easy
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
The eID Easy WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error parameter found in the ~/admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.6.
Vulnerable Configurations
References
- https://plugins.trac.wordpress.org/browser/smart-id/trunk/admin.php?rev=2451347#L30
- https://plugins.trac.wordpress.org/browser/smart-id/trunk/admin.php?rev=2451347#L30
- https://www.wordfence.com/vulnerability-advisories/#CVE-2021-34650
- https://www.wordfence.com/vulnerability-advisories/#CVE-2021-34650