Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-44082
HistoryMar 29, 2022 - 11:15 p.m.

Cross site scripting

2022-03-2923:15:00
PRIOn knowledge base
www.prio-n.com
3

8 High

AI Score

Confidence

High

0.019 Low

EPSS

Percentile

88.5%

textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by uploading a webshell. To do so they must first steal the CSRF token before submitting a file upload request.

CPENameOperatorVersion
textpatterneq4.8.7

8 High

AI Score

Confidence

High

0.019 Low

EPSS

Percentile

88.5%

Related for PRION:CVE-2021-44082