CVE-2021-43810
Last modified
CVE-2021-43810 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vulnerability is present in Admidio prior to version 4.0.12. EPSS estimates a 5.78% chance of exploitation in the next 30 days.
Description
Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vulnerability is present in Admidio prior to version 4.0.12. The Reflected XSS vulnerability occurs because redirect.php does not properly validate the value of the url parameter. Through this vulnerability, an attacker is capable to execute malicious scripts. This issue is patched in version 4.0.12.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Admidio | Admidio | < 4.0.12 |
References
- https://github.com/Admidio/admidio/commit/c043267d362f7813543cc2785119bf3e3e54fe21Patch, Third Party Advisory
- https://github.com/Admidio/admidio/commit/fcb0609abc1d2f65bc1377866bd678e5d891404bPatch, Third Party Advisory
- https://github.com/Admidio/admidio/releases/tag/v4.0.12Patch, Release Notes, Third Party Advisory
- https://github.com/Admidio/admidio/security/advisories/GHSA-3qgf-qgc3-42hhThird Party Advisory
- https://github.com/Admidio/admidio/commit/c043267d362f7813543cc2785119bf3e3e54fe21Patch, Third Party Advisory
- https://github.com/Admidio/admidio/commit/fcb0609abc1d2f65bc1377866bd678e5d891404bPatch, Third Party Advisory
- https://github.com/Admidio/admidio/releases/tag/v4.0.12Patch, Release Notes, Third Party Advisory
- https://github.com/Admidio/admidio/security/advisories/GHSA-3qgf-qgc3-42hhThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-43810?
How severe is CVE-2021-43810?
How do I fix CVE-2021-43810?
Are you affected by CVE-2021-43810?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
