CVE-2021-44116

MEDIUM6.1EPSS 0.24%

Cross-site Scripting in Anchor CMS

Published: 1/5/2022Modified: 11/8/2023
Also known as:GHSA-7mq6-cp5m-f4j5

Description

Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column to upload the title and content containing malicious code to achieve the purpose of obtaining the administrator cookie, thereby achieving other malicious operations.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (3)