CVE-2021-24237
22.04.2021, 21:15
The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not properly sanitise the keyword_search, search_radius. _bedrooms and _bathrooms GET parameters before outputting them in its properties page, leading to an unauthenticated reflected Cross-Site Scripting issue.
Vendor | Product | Version |
---|---|---|
purethemes | findeo | 𝑥 < 1.3.1 |
purethemes | realteo | 𝑥 < 1.2.4 |
𝑥
= Vulnerable software versions
References