Reflected Cross-Site Scripting Vulnerability in MaxSite CMS
CVE-2021-35265 
6.1MEDIUM
What is CVE-2021-35265?
A reflected cross-site scripting (XSS) vulnerability exists in MaxSite CMS prior to version 106. This flaw enables remote attackers to exploit the vulnerability by injecting arbitrary web scripts into pages via the product/page/* endpoint. Such vulnerabilities can lead to a range of security threats, including session hijacking and data theft, as attackers could manipulate the content seen by users.
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
 Low
Availability:
 Low
Attack Vector:
Network
Attack Complexity:
 Low
Privileges Required:
 None
User Interaction:
 Required
Scope:
 Changed
Timeline
- Vulnerability published 
- Vulnerability Reserved 
