Vulnerabilities > CVE-2021-39346 - Unspecified vulnerability in Supsystic Easy Google Maps
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/modules/marker_groups/views/tpl/mgrEditMarkerGroup.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.9.33. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.
Vulnerable Configurations
References
- https://github.com/BigTiger2020/word-press/blob/main/Google%20Maps%20Easy.md
- https://github.com/BigTiger2020/word-press/blob/main/Google%20Maps%20Easy.md
- https://plugins.trac.wordpress.org/changeset/2620851/google-maps-easy/trunk/modules/marker_groups/views/tpl/mgrEditMarkerGroup.php
- https://plugins.trac.wordpress.org/changeset/2620851/google-maps-easy/trunk/modules/marker_groups/views/tpl/mgrEditMarkerGroup.php
- https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39346
- https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39346