Lucene search

K
cvelistMitreCVELIST:CVE-2021-44082
HistoryMar 29, 2022 - 10:50 p.m.

CVE-2021-44082

2022-03-2922:50:40
mitre
www.cve.org

8.3 High

AI Score

Confidence

High

0.019 Low

EPSS

Percentile

88.5%

textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by uploading a webshell. To do so they must first steal the CSRF token before submitting a file upload request.

8.3 High

AI Score

Confidence

High

0.019 Low

EPSS

Percentile

88.5%

Related for CVELIST:CVE-2021-44082