Reflected Cross-Site Scripting Vulnerability in MaxSite CMS
CVE-2021-35265

6.1MEDIUM

Key Information:

Vendor

Maxsite

Vendor
CVE Published:
3 August 2021

What is CVE-2021-35265?

A reflected cross-site scripting (XSS) vulnerability exists in MaxSite CMS prior to version 106. This flaw enables remote attackers to exploit the vulnerability by injecting arbitrary web scripts into pages via the product/page/* endpoint. Such vulnerabilities can lead to a range of security threats, including session hijacking and data theft, as attackers could manipulate the content seen by users.

References

EPSS Score

5% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.