Lucene search

K
cvelistGitHub_MCVELIST:CVE-2021-43810
HistoryDec 07, 2021 - 10:00 p.m.

CVE-2021-43810 Cross-site Scripting (XSS) when redirect an url

2021-12-0722:00:12
CWE-79
GitHub_M
www.cve.org
1

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.2 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.7%

Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vulnerability is present in Admidio prior to version 4.0.12. The Reflected XSS vulnerability occurs because redirect.php does not properly validate the value of the url parameter. Through this vulnerability, an attacker is capable to execute malicious scripts. This issue is patched in version 4.0.12.

CNA Affected

[
  {
    "product": "admidio",
    "vendor": "Admidio",
    "versions": [
      {
        "status": "affected",
        "version": "< 4.0.12"
      }
    ]
  }
]

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.2 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.7%

Related for CVELIST:CVE-2021-43810