CVE-2021-24921
21.02.2022, 11:15
The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
Vendor | Product | Version |
---|---|---|
sigmaplugin | advanced_database_cleaner | 𝑥 < 3.0.4 |
𝑥
= Vulnerable software versions