A cross-site scripting (XSS) vulnerability in many forms of Wikindx before 5.7.0 and 6.x through 6.4.0 allows remote attackers to inject arbitrary web script or HTML via the message parameter to index.php?action=initLogon or modules/admin/DELETEIMAGES.php.
References
Link | Resource |
---|---|
https://sourceforge.net/p/wikindx/news/2021/01/wikindx-v641-released/ | Release Notes Third Party Advisory |
https://sourceforge.net/projects/wikindx/ | Product Third Party Advisory |
https://sourceforge.net/p/wikindx/news/2021/01/wikindx-v641-released/ | Release Notes Third Party Advisory |
https://sourceforge.net/projects/wikindx/ | Product Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:21
Type | Values Removed | Values Added |
---|---|---|
References | () https://sourceforge.net/p/wikindx/news/2021/01/wikindx-v641-released/ - Release Notes, Third Party Advisory | |
References | () https://sourceforge.net/projects/wikindx/ - Product, Third Party Advisory |
Information
Published : 2021-02-01 22:15
Updated : 2024-11-21 06:21
NVD link : CVE-2021-3340
Mitre link : CVE-2021-3340
CVE.ORG link : CVE-2021-3340
JSON object : View
Products Affected
wikindx_project
- wikindx
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')