CVE-2021-23260 Vulnerability Details
/
/
/
CVE-2021-23260 Metadata Quick Info
CVE Published: 02/12/2021 |
CVE Updated: 16/09/2024 |
CVE Year: 2021
Source: crafter |
Vendor: Crafter Software |
Product: Crafter CMS
Status : PUBLISHED
CVE-2021-23260 Description
Authenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and other users of the same site.
Metrics
CVSS Version: 3.1 |
Base Score: 6.5 MEDIUM
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:L
l➤ Exploitability Metrics:
Attack Vector (AV)* NETWORK
Attack Complexity (AC)* HIGH
Privileges Required (PR)* LOW
User Interaction (UI)* REQUIRED
Scope (S)* CHANGED
l➤ Impact Metrics:
Confidentiality Impact (C)* HIGH
Integrity Impact (I)* NONE
Availability Impact (A)* LOW
Weakness Enumeration (CWE)
CWE-ID: CWE-79
CWE Name: CWE-79 Cross-site Scripting (XSS)
Source: Crafter Software
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).