Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-4252— WP-Ban ban-options.php toggle_checkbox cross site scripting

CVSS 3.5 · Low EPSS 0.27% · P50
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-4252

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
WP-Ban ban-options.php toggle_checkbox cross site scripting
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability, which was classified as problematic, has been found in WP-Ban. This issue affects the function toggle_checkbox of the file ban-options.php. The manipulation of the argument $_SERVER["HTTP_USER_AGENT"] leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 13e0b1e922f3aaa3f8fcb1dd6d50200dd693fd76. It is recommended to apply a patch to fix this issue. The identifier VDB-216209 was assigned to this vulnerability.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
对消息或数据结构的处理不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
WP-Ban 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WP-Ban是Lester Chan个人开发者的一个通过 IP、IP 范围、主机名、用户代理和引用 url 禁止用户访问 WordPress 的博客。 WP-Ban存在安全漏洞,该漏洞源于其ban-options.php文件的toggle_checkbox函数对某参数的操作允许攻击者实现跨站脚本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
unspecifiedWP-Ban n/a -

II. Public POCs for CVE-2021-4252

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-4252

登录查看更多情报信息。

Same Patch Batch · unspecified · 2022-12-18 · 7 CVEs total

CVE-2021-42494.3 MEDIUMxml-conduit DOCTYPE Entity Expansion Parse.hs infinite loop
CVE-2022-46034.3 MEDIUMppp pppdump pppdump.c dumpppp array index
CVE-2021-42513.5 LOWas include.cdn.php getFullURL cross site scripting
CVE-2022-45933.5 LOWretra-system cross site scripting
CVE-2022-45953.5 LOWdjango-openipam exposed_hosts.html cross site scripting
CVE-2022-45963.5 LOWShoplazza Add Blog Post cross site scripting

IV. Related Vulnerabilities

V. Comments for CVE-2021-4252

No comments yet


Leave a comment