CVE-2021-45843

glFusion CMS v1.7.9 is affected by a reflected Cross Site Scripting (XSS) vulnerability. The value of the title request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. This input was echoed unmodified in the application's response.
Configurations

Configuration 1 (hide)

cpe:2.3:a:glfusion:glfusion:1.7.9:*:*:*:*:*:*:*

History

30 Sep 2022, 19:40

Type Values Removed Values Added
First Time Glfusion glfusion
Glfusion
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References (MISC) https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/glfusion/XSS-Reflected - (MISC) https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/glfusion/XSS-Reflected - Exploit, Third Party Advisory
CPE cpe:2.3:a:glfusion:glfusion:1.7.9:*:*:*:*:*:*:*

29 Sep 2022, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-09-29 03:15

Updated : 2023-12-10 14:35


NVD link : CVE-2021-45843

Mitre link : CVE-2021-45843

CVE.ORG link : CVE-2021-45843


JSON object : View

Products Affected

glfusion

  • glfusion
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')