CVE-2021-24510
13.09.2021, 18:15
The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter before outputting back in the admin dashboard when editing an Event, leading to a reflected Cross-Site Scripting issueEnginsight
Vendor | Product | Version |
---|---|---|
mf_gig_calendar_project | mf_gig_calendar | 𝑥 ≤ 1.1 |
𝑥
= Vulnerable software versions