CVE-2021-40238

A Cross Site Scriptiong (XSS) vulnerability exists in the admin panel in Webuzo < 2.9.0 via an HTTP request to a non-existent page, which is activated by administrators viewing the "Error Log" page. An attacker can leverage this to achieve Unauthenticated Remote Code Execution via the "Cron Jobs" functionality of Webuzo.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:webuzo:webuzo:*:*:*:*:*:*:*:*

Information

Published : 2021-09-15 10:15

Updated : 2021-09-28 08:44


NVD link : CVE-2021-40238

Mitre link : CVE-2021-40238


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

webuzo

  • webuzo