Skip to content

Add CVE-2021-24876.yaml (vKEV)#13183

Merged
pussycat0x merged 3 commits intomainfrom
CVE-2021-24876
Sep 16, 2025
Merged

Add CVE-2021-24876.yaml (vKEV)#13183
pussycat0x merged 3 commits intomainfrom
CVE-2021-24876

Conversation

@DhiyaneshGeek
Copy link
Copy Markdown
Member

@DhiyaneshGeek DhiyaneshGeek commented Sep 10, 2025

Template / PR Information

  • Fixed CVE-2020-XXX / Added CVE-2020-XXX / Updated CVE-2020-XXX
  • References:

Template Validation

I've validated this template locally?

  • YES
  • NO

Additional Details (leave it blank if not applicable)

Additional References:

@github-actions
Copy link
Copy Markdown
Contributor

⚠️ Weak matcher detected

It looks like Nuclei has found some results on the honeypot target.

To improve the accuracy of these results and avoid any false positives, please adjust the matchers as needed. This will help in providing more reliable and precise results.

Template ID
CVE-2021-24876

Ref 0315b6c

@github-actions github-actions bot added the false-positive Nuclei template reporting invalid/unexpected result label Sep 10, 2025
@DhiyaneshGeek DhiyaneshGeek mentioned this pull request Sep 10, 2025
1 task
@popcorn94
Copy link
Copy Markdown
Contributor

Sorry is this template valid?

@DhiyaneshGeek
Copy link
Copy Markdown
Member Author

Hi @popcorn94,

I’ve raised a new PR since the existing one had several conflicts. The team is currently validating the template, and I’ll update you once the first round of validation is complete.

Thanks!

@popcorn94
Copy link
Copy Markdown
Contributor

popcorn94 commented Sep 11, 2025

Hi @DhiyaneshGeek ,

Sorry , below is a updated template for your team to validate which won't be false positive as I added more words
CVE-2021-24876.yaml

@DhiyaneshGeek DhiyaneshGeek changed the title Add CVE-2021-24876.yaml Add CVE-2021-24876.yaml (CVE-2021-24876) Sep 15, 2025
@DhiyaneshGeek DhiyaneshGeek changed the title Add CVE-2021-24876.yaml (CVE-2021-24876) Add CVE-2021-24876.yaml (KEV) Sep 15, 2025
@DhiyaneshGeek DhiyaneshGeek changed the title Add CVE-2021-24876.yaml (KEV) Add CVE-2021-24876.yaml (vKEV) Sep 16, 2025
Updated the CVE-2021-24876 YAML file to include additional matchers for XSS detection.
Updated CVE-2021-24876 entry to reflect changes in vulnerability details and remediation.
@DhiyaneshGeek DhiyaneshGeek added Done Ready to merge and removed false-positive Nuclei template reporting invalid/unexpected result labels Sep 16, 2025
@DhiyaneshGeek
Copy link
Copy Markdown
Member Author

DhiyaneshGeek commented Sep 16, 2025

Validated Locally

LGTM !

                     __     _
   ____  __  _______/ /__  (_)
  / __ \/ / / / ___/ / _ \/ /
 / / / / /_/ / /__/ /  __/ /
/_/ /_/\__,_/\___/_/\___/_/   v3.4.10

		projectdiscovery.io

[INF] Current nuclei version: v3.4.10 (latest)
[INF] Current nuclei-templates version: v10.2.8 (latest)
[INF] New templates added in latest release: 114
[INF] Templates loaded for current scan: 1
[WRN] Loading 1 unsigned templates for scan. Use with caution.
[INF] Targets loaded for current scan: 1
[CVE-2021-24876] [http] [medium] http://localhost:8080/wp-admin/admin.php?page=registrations-for-the-events-calendar&tab=registrations&v="+style=animation-name:rotation+onanimationstart=alert(document.domain)//
[INF] Scan completed in 1.054728834s. 1 matches found.
image

@pussycat0x
Copy link
Copy Markdown
Contributor

hello @popcorn94 ,Thank you for sharing this template with the community and for your contribution to this project.

@DhiyaneshGeek
Copy link
Copy Markdown
Member Author

Hi @popcorn94,

Thank you for sharing the template and contributing to the project. We’ve made the necessary changes to improve detection and updated the matcher to address false positives.

@pussycat0x pussycat0x merged commit 2350de3 into main Sep 16, 2025
3 checks passed
@pussycat0x pussycat0x deleted the CVE-2021-24876 branch September 16, 2025 04:05
@algora-pbc
Copy link
Copy Markdown

algora-pbc bot commented Sep 16, 2025

🎉🎈 @popcorn94 has been awarded $200 by ProjectDiscovery! 🎈🎊

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Done Ready to merge 💰 Rewarded

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants