Cross Site Scripting Vulnerability in Pixelimity by Pixelimity
CVE-2021-29056

4.8MEDIUM

Key Information:

Vendor

Pixelimity

Vendor
CVE Published:
17 August 2021

What is CVE-2021-29056?

A Cross Site Scripting (XSS) vulnerability has been identified in Pixelimity version 1.0, which allows an attacker to exploit the HTTP POST parameter at admin/setting.php. This security flaw could potentially enable malicious users to inject arbitrary JavaScript code into the web application, leading to unauthorized actions and the compromise of user data. Organizations utilizing this version of Pixelimity are encouraged to patch the vulnerability promptly to safeguard against potential exploitation.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.