CVE-2021-24476
02.08.2021, 11:15
The Steam Group Viewer WordPress plugin through 2.1 does not sanitise or escape its "Steam Group Address" settings before outputting it in the page, leading to an authenticated Stored Cross-Site Scripting issue
Vendor | Product | Version |
---|---|---|
steam_group_viewer_project | steam_group_viewer | 𝑥 ≤ 2.1 |
𝑥
= Vulnerable software versions