← Back

CVE-2021-25102

nvd nist
Published: May 2, 2022Modified: Nov 21, 2024

JSON object

Loading...
4.7
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.6 / Impact: 2.7
Source: NVD

Description

The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect_to parameter before using it to redirect user, either via a Location header, or meta url attribute, when the Rename Login Page is active, which could lead to an Arbitrary Redirect as well as Cross-Site Scripting issue. Exploitation of this issue requires the Login Page URL value to be known, which should be hard to guess, reducing the risk

Affected (1)

All In One Wp Security & Firewall
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 4.4.11

References (2)

Source: contact@wpscan.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.