Cross-Site Scripting Vulnerability in SourceCodester Content Management System
CVE-2021-25197

6.1MEDIUM

What is CVE-2021-25197?

The SourceCodester Content Management System version 1.0 is susceptible to a cross-site scripting (XSS) vulnerability. This security flaw enables remote attackers to inject arbitrary web scripts or HTML into the application through the search parameter in the admin panel's new content section. Exploiting this vulnerability can lead to data theft, session hijacking, and other malicious activities that compromise user information and system integrity.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.