Security Advisory

CVE-2021-24346

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-06-14 13:37:12
Last updated 2024-08-03 19:28:23
Assigner WPScan
State PUBLISHED

Description

The Stock in & out WordPress plugin through 1.0.4 has a search functionality, the lowest accessible level to it being contributor. The srch POST parameter is not validated, sanitised or escaped before using it in the echo statement, leading to a reflected XSS issue