CVE-2021-24335
Car Repair Services < 4.0 - Unauthenticated Reflected XSS & XFS
Vexday Risk Score
18Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 3.9%KEV nãoPoC —Nuclei simMetasploit —Patch —
Lifecycle
01 Jun 2021Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
The Car Repair Services & Auto Mechanic WordPress theme before 4.0 did not properly sanitise its serviceestimatekey search parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting issue
Affected products
Unknown · Car Repair Services & Auto MechanicWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →