peter bassill · operator
$ cve CVE-2021-24299 JSON

CVE-2021-24299 EXPLOIT

6.1
MEDIUM · CVSS 3.1 · EPSS 5.5% (pctl 93)

Patch early

A public exploit exists.

Description

The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservations are stored and can be listed on an 'Upcoming' page provided by the plugin. An unauthenticated user can fill in the form to make a restaurant reservation. The form to make a restaurant reservation field called 'Comment' does not use proper input validation and can be used to store XSS payloads. The XSS payloads will be executed when the plugin user goes to the 'Upcoming' page, which is an external website https://upcoming.reservationdiary.eu/ loaded in an iframe, and the stored reservation with XSS payload is loaded.

Scoring

CVSS6.1 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS5.5% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2021-05-17
Last modified2026-06-17

Affected (1)

VendorProduct
catzsoftredi restaurant reservation

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD