CVE-2021-24438

CVE-2021-24438: ShareThis Dashboard for Google Analytics < 2.5.2 - Reflected Cross-Site Scripting (XSS)

Vendor Unknown
Product ShareThis Dashboard for Google Analytics
Weakness CWE-79 · XSS
Published August 30, 2021
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' parameter in the stats view before outputting it back in an attribute when the plugin is connected to a Google Analytics account, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

Key dates

02Disclosure timeline

August 30, 2021 CVE published
August 3, 2024 Record updated