CVE-2021-24302
The Hana Flv Player WordPress plugin through 3.1.3 is vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the 'Default Skin' field.
- Affected products
- Hana Flv Player
- Neox Hana Flv Player
- ≤ 3.1.3
- Fix
- Available
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 0.6% (47th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2021-05-24
CVE-2021-24302 at NVD
1 known exploit for CVE-2021-24302
Proof-of-concept code and exploit modules indexed by Sploitus