S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24298 Scanner

CVE-2021-24298 scanner - Cross-Site Scripting (XSS) vulnerability in Simple Giveaways

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24298
6.1
CVSS

The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Simple Giveaways – Grow your business, email lists and traffic with contestsby Igor Benic
AFFECTED< 2.36.2SAFE ✓≥ 2.36.2
Updated Aug 21, 2026View on NVD →
Detail

Simple Giveaways is a popular software product designed to facilitate the hosting of online giveaways on websites. It allows website owners to create and manage unique giveaways, making it easier for them to increase engagement and interaction with their audience. With Simple Giveaways, website owners can easily add incentives to their promotions, improve customer loyalty, and generate new customer leads. The intuitive software also features multiple giveaway options, custom designs, and other additional customization options.

CVE-2021-24298 is a vulnerability that was recently discovered in Simple Giveaways. The issue stemmed from the fact that the method and share GET parameters of the Giveaway pages were not sanitised, validated, or escaped before being output back in the pages. This made it possible for hackers and cybercriminals to exploit the vulnerability by injecting malicious code into the giveaway pages.

When exploited, CVE-2021-24298 could pose a significant threat to the security and privacy of website owners and their users. Attackers could use the vulnerability to conduct a variety of malicious activities, including stealing sensitive data, monitoring user activity, and executing unauthorized code. Additionally, they could use the vulnerability to gain access to sensitive information, such as passwords, usernames, and credit card details.

In conclusion, the CVE-2021-24298 vulnerability discovered in Simple Giveaways highlights the importance of taking a proactive approach to cybersecurity. With the help of s4e.io's pro features, website owners can easily and quickly identify vulnerabilities in their digital assets and take the necessary steps to protect against potential threats. By prioritizing cybersecurity, website owners can ensure that their online giveaways remain a safe and secure way to engage with their audience, build customer loyalty, and generate new leads effectively.

 

REFERENCES

Solution Advice

Thankfully, there are several precautions that website owners can take to protect against the CVE-2021-24298 vulnerability. These include:

  • Regularly updating and patching Simple Giveaways
  • Enabling recommended security measures, such as firewalls and antivirus software
  • Performing regular vulnerability scans and penetration testing
  • Developing a comprehensive incident response plan
  • Monitoring website activity and user behaviour for suspicious activity

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24298 scanner - Cross-Site Scripting (XSS) vulnerability in Simple Giveaways | S4E