CVE-2021-24176

The JH 404 Logger WordPress plugin through 1.1 doesn't sanitise the referer and path of 404 pages, when they are output in the dashboard, which leads to executing arbitrary JavaScript code in the WordPress dashboard.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jh_404_logger_project:jh_404_logger:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2021-04-05 19:15

Updated : 2024-11-21 05:52


NVD link : CVE-2021-24176

Mitre link : CVE-2021-24176

CVE.ORG link : CVE-2021-24176


JSON object : View

Products Affected

jh_404_logger_project

  • jh_404_logger
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')