CVE-2021-45843

glFusion CMS v1.7.9 is affected by a reflected Cross Site Scripting (XSS) vulnerability. The value of the title request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. This input was echoed unmodified in the application's response.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:glfusion:glfusion:1.7.9:*:*:*:*:*:*:*

Information

Published : 2022-09-28 20:15

Updated : 2022-09-30 12:40


NVD link : CVE-2021-45843

Mitre link : CVE-2021-45843


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

glfusion

  • glfusion