CVE-2021-24167
EUVD-2021-1108105.04.2021, 19:15
When visiting a site running Web-Stat < 1.4.0, the "wts_web_stat_load_init" function used the visitor’s browser to send an XMLHttpRequest request to https://wts2.one/ajax.htm?action=lookup_WP_account.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| web-stat | web-stat | 𝑥 < 1.4.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration