CVE-2021-24177Cross-site Scripting in File Manager

Severity
5.4MEDIUMNVD
EPSS
0.2%
top 52.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 5
Latest updateMay 24

Description

In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hwf5-vp84-w4x7: In the default configuration of the File Manager WordPress plugin before 72022-05-24
CVEList
WP File Manager < 7.1 - Reflected Cross-Site Scripting (XSS)2021-04-05
CVE-2021-24177 — Cross-site Scripting in File Manager | cvebase