CVE-2021-24323

MEDIUM4.8EPSS 0.38%

Woocommerce Cross-site Scripting via Additional tax classes field when taxes are enabled

Published: 5/24/2022Modified: 2/16/2024
Also known as:GHSA-mp46-7x6q-f28m

Description

When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when the unfiltered_html is disabled

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.8CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

References (4)