CVE-2021-24467 - CVE House
Back to Database
Status published Medium CVE-2021-24467

Leaflet Map < 3.0.0 - Arbitrary Settings Update via CSRF Leading to Stored XSS

Vulnerability Description

The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows attackers to make a logged in admin update the settings via a Cross-Site Request Forgery attack. This could lead to Cross-Site Scripting issues by either changing the URL of the JavaScript library being used, or using malicious attributions which will be executed in all page with an embed map from the plugin

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-24467

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • apple502j