The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting attacks by placing a payload in the notes field, when an administrator or any authenticated user go to the chat the XSS will be automatically executed.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/19d101aa-4b60-4db4-a33b-86c826b288b0 | third party advisory exploit |
https://medium.com/%40lijohnjefferson/cve-2021-24807-6bc22af2a444 | |
https://github.com/itsjeffersonli/CVE-2021-24807 | third party advisory exploit |