CVE-2021-47917
Last modified
CVE-2021-47917 is a medium-severity vulnerability rated 5.1/10 on the CVSS scale. Simple CMS 2.1 contains a persistent cross-site scripting vulnerability in user input parameters that allows remote attackers to inject malicious script code. Attackers can exploit the newUser and editUser modules to inject persistent scripts that execute on user list preview, potentially leading to session hijacking and application manipulation.. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Simple CMS 2.1 contains a persistent cross-site scripting vulnerability in user input parameters that allows remote attackers to inject malicious script code. Attackers can exploit the newUser and editUser modules to inject persistent scripts that execute on user list preview, potentially leading to session hijacking and application manipulation.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Simplephpscripts | Simple Cms Php | 2.1 |
References
- https://www.vulnerability-lab.com/get_content.php?id=2302Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2021-47917?
How severe is CVE-2021-47917?
How do I fix CVE-2021-47917?
Are you affected by CVE-2021-47917?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
