A cross-site scripting (XSS) vulnerability in many forms of Wikindx before 5.7.0 and 6.x through 6.4.0 allows remote attackers to inject arbitrary web script or HTML via the message parameter to index.php?action=initLogon or modules/admin/DELETEIMAGES.php.
References
Link | Resource |
---|---|
https://sourceforge.net/p/wikindx/news/2021/01/wikindx-v641-released/ | Release Notes Third Party Advisory |
https://sourceforge.net/projects/wikindx/ | Product Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-02-01 14:15
Updated : 2021-02-04 10:10
NVD link : CVE-2021-3340
Mitre link : CVE-2021-3340
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
wikindx_project
- wikindx