Cross Site Scripting Vulnerability in Anchor CMS by Anchor
CVE-2021-44116

6.1MEDIUM

Key Information:

Vendor

Anchorcms

Vendor
CVE Published:
15 December 2021

What is CVE-2021-44116?

A Cross Site Scripting vulnerability exists in Anchor CMS versions up to 0.12.7. This flaw allows attackers to exploit the posts column in posts.php to upload malicious titles and content. By doing so, they can execute scripts that may capture the administrator's cookies, facilitating further unauthorized actions within the application.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.