Titan Framework <= (Various Versions) - Reflected Cross-Site Scripting

2021-08-09 00:00
iohex

Strategic Overview

Status
Unpatched
Affected PluginAMP extensions
Affected Version*
CVSS6.1Medium
CVECVE-2021-24435
View all AMP extensions vulnerabilities

Vulnerability Overview

The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C

Titan Framework <= (Various Versions) - Reflected Cross-Site Scripting (CVE-2021-24435)