Lucene search

K
cvelistMitreCVELIST:CVE-2021-44118
HistoryJan 26, 2022 - 11:07 a.m.

CVE-2021-44118

2022-01-2611:07:57
mitre
www.cve.org
4
spip 4.0.0
cross site scripting
xss
web pages
authenticated attacker
svg file
client side

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

25.8%

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users (stored XSS).

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

25.8%