CVE-2021-24787

Client Invoicing by Sprout Invoices < 19.9.7 - Admin+ Stored Cross-Site Scripting

The Client Invoicing by Sprout Invoices WordPress plugin before 19.9.7 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed


We have discovered 77 live websites that are affected by CVE-2021-24787.

Run a Free Instant Scan




Affected Software

Product  Sprout Invoices
Category Wordpress Plugins
Vulnerable Domains77 live websites (18% of Sprout Invoices install base)
Vulnerable Versions
  • from 0 through 19.9.7
Vulnerable Versions Count14 versions ( 33% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Nov 17, 2021
  • Updated - Aug 3, 2024

Credits

  • Dipak Panchal

Website Distribution by Country

Number of websites using CVE-2021-24787
United States40 websites



GB9 websites
France4 websites
Australia3 websites
Switzerland3 websites
Cyprus3 websites
Spain2 websites
Italy2 websites
Romania2 websites
Slovenia2 websites

Website Distribution by TLD

Number of websites using CVE-2021-24787
.com54 websites
.fr3 websites
.co.uk2 websites
.com.au2 websites
.es2 websites
.ch1 websites
.co1 websites
.com.br1 websites
.cz1 websites
.io1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-24787

Top websites that are affected by CVE-2021-24787. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.****.es Spain**,***
******************.com United States***,***
**********.com United States***,***
*******.co United States*,***,***
*****.com United States*,***,***
*************.com GB*,***,***
*******************.it Italy*,***,***
*******************.com Canada*,***,***
*****.com GB*,***,***
**************.com United States*,***,***
See full domain list

FAQ

CVE-2021-24787 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Sprout Invoices
A total of 77 websites have been identified as vulnerable to CVE-2021-24787, based on global website indexing conducted by WebTechSurvey.
The Sprout Invoices is affected by the CVE-2021-24787 vulnerability.
Sprout Invoices versions up to 19.9.7 are vulnerable to CVE-2021-24787.
CVE-2021-24787 is resolved in version 19.9.7 of Sprout Invoices.