CVE-2021-24167
05.04.2021, 19:15
When visiting a site running Web-Stat < 1.4.0, the "wts_web_stat_load_init" function used the visitors browser to send an XMLHttpRequest request to https://wts2.one/ajax.htm?action=lookup_WP_account.Enginsight
Vendor | Product | Version |
---|---|---|
web-stat | web-stat | 𝑥 < 1.4.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration