CVE-2021-3258

Question2Answer Q2A Ultimate SEO Version 1.3 is affected by cross-site scripting (XSS), which may lead to arbitrary remote code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:qa-themes:q2a_ultimate_seo:1.3:*:*:*:*:question2answer:*:*

History

21 Nov 2024, 06:21

Type Values Removed Values Added
References () https://github.com/q2a-projects/Q2A-Ultimate-SEO/commit/20069f28147c6f2c3acca4e3f6f5154537c5d536 - Patch, Third Party Advisory () https://github.com/q2a-projects/Q2A-Ultimate-SEO/commit/20069f28147c6f2c3acca4e3f6f5154537c5d536 - Patch, Third Party Advisory
References () https://nirmaldahal.com.np/sxss-to-defacement-and-account-takeover/ - Exploit, Third Party Advisory () https://nirmaldahal.com.np/sxss-to-defacement-and-account-takeover/ - Exploit, Third Party Advisory
References () https://www.question2answer.org/qa/58520/important-q2a-ultimate-seo-important-update - Release Notes, Vendor Advisory () https://www.question2answer.org/qa/58520/important-q2a-ultimate-seo-important-update - Release Notes, Vendor Advisory

Information

Published : 2021-02-05 16:15

Updated : 2024-11-21 06:21


NVD link : CVE-2021-3258

Mitre link : CVE-2021-3258

CVE.ORG link : CVE-2021-3258


JSON object : View

Products Affected

qa-themes

  • q2a_ultimate_seo
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')