Stored Cross-Site Scripting Vulnerability in cszcms by cskaza
CVE-2021-3224

5.4MEDIUM

Key Information:

Vendor

Cszcms

Status
Vendor
CVE Published:
10 March 2021

What is CVE-2021-3224?

A stored cross-site scripting (XSS) vulnerability exists in the cszcms version 1.2.9 within the /admin/pages/new endpoint. This vulnerability allows attackers to inject and store malicious scripts in the web application, leading to potential session hijacking, defacement, or the unauthorized access of sensitive user data. Proper input validation measures should be implemented to mitigate the risk associated with this vulnerability.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-3224 : Stored Cross-Site Scripting Vulnerability in cszcms by cskaza