Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "module" parameter.
References
Link | Resource |
---|---|
https://github.com/xoffense/POC/blob/main/Clansphere%202011.4%20%22module%22%20xss.md | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2021-03-23 14:15
Updated : 2024-02-04 21:23
NVD link : CVE-2021-27309
Mitre link : CVE-2021-27309
CVE.ORG link : CVE-2021-27309
JSON object : View
Products Affected
csphere
- clansphere
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')