Lucene search

K
osvGoogleOSV:CVE-2021-44082
HistoryMar 29, 2022 - 11:15 p.m.

CVE-2021-44082

2022-03-2923:15:07
Google
osv.dev
5

6.5 Medium

AI Score

Confidence

High

0.019 Low

EPSS

Percentile

88.5%

textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by uploading a webshell. To do so they must first steal the CSRF token before submitting a file upload request.

6.5 Medium

AI Score

Confidence

High

0.019 Low

EPSS

Percentile

88.5%

Related for OSV:CVE-2021-44082