CVE-2021-37393
Last modified
CVE-2021-37393 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page. Attacker can use "update password" function to inject XSS payloads into nickname variable, and achieve stored XSS. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page. Attacker can use "update password" function to inject XSS payloads into nickname variable, and achieve stored XSS. Users who view the articles published by the injected user will trigger the XSS.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rpcms | Rpcms | <= 1.8 |
References
- https://gist.github.com/victomteng1997/bfa1e0e07dd22f7e0b13256eda79626fExploit, Third Party Advisory
- https://gist.github.com/victomteng1997/bfa1e0e07dd22f7e0b13256eda79626fExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-37393?
How severe is CVE-2021-37393?
How do I fix CVE-2021-37393?
Are you affected by CVE-2021-37393?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
