Reflected XSS Vulnerability in ICEcoder 8.0 by ICEcoder
CVE-2021-32106

5.4MEDIUM

Key Information:

Vendor

Icecoder

Status
Vendor
CVE Published:
8 June 2021

What is CVE-2021-32106?

ICEcoder 8.0 contains a reflected cross-site scripting (XSS) vulnerability in the multipe-results.php file. This flaw is caused by inadequate sanitization of input in the _GET['replace'] variable, which allows attackers to inject and execute arbitrary JavaScript code. This vulnerability poses potential risks for end-users, enabling attackers to exploit vulnerable instances of ICEcoder by crafting malicious links that can manipulate the execution of JavaScript in the victim's browser. Immediate action is recommended to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.