Lucene search

K
nvd[email protected]NVD:CVE-2021-44076
HistorySep 15, 2022 - 1:15 p.m.

CVE-2021-44076

2022-09-1513:15:09
CWE-79
web.nvd.nist.gov
2
crushftp 9
stored cross-site scripting
webinterface/usermanager

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

24.8%

An issue was discovered in CrushFTP 9. The creation of a new user through the /WebInterface/UserManager/ interface allows an attacker, with access to the administration panel, to perform Stored Cross-Site Scripting (XSS). The payload can be executed in multiple scenarios, for example when the user’s page appears in the Most Visited section of the page.

Affected configurations

Nvd
Node
crushftpcrushftpRange9.0.09.4.0_15
VendorProductVersionCPE
crushftpcrushftp*cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:*

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

24.8%

Related for NVD:CVE-2021-44076