Cross-site Scripting Vulnerability in Spotweb by Spotweb
CVE-2021-40972

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
1 October 2021

What is CVE-2021-40972?

A cross-site scripting vulnerability exists in Spotweb versions 1.5.1 and earlier, specifically in the templates/installer/step-004.inc.php file. This flaw allows remote attackers to inject malicious web scripts or HTML code through the 'mail' parameter, potentially compromising user data and application integrity. Proper input validation measures should be implemented to mitigate these risks and secure the application.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.