CVE-2021-37365

CTparental before 4.45.03 is vulnerable to cross-site scripting (XSS) in the CTparental admin panel. In bl_categires_help.php, the 'categories' variable is assigned with the content of the query string param 'cat' without sanitization or encoding, enabling an attacker to inject malicious code into the output webpage.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:ctparental_project:ctparental:*:*:*:*:*:*:*:*

Information

Published : 2021-08-10 10:15

Updated : 2021-08-13 07:56


NVD link : CVE-2021-37365

Mitre link : CVE-2021-37365


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

ctparental_project

  • ctparental