6.1
CVE-2020-21316
- EPSS 1.12%
- Veröffentlicht 15.06.2021 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:12:30
- CVE-Watchlists
- Unerledigt
A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script and stolen administrator cookies via the nickname parameter and gain access to the admin panel.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.12% | 0.619 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://gist.github.com/T-pod/d9405dbd61243990d65d55c5df0fcbe6
https://github.com/94fzb/zrlog/commit/b921c1ae03b8290f438657803eee05226755c941
https://github.com/94fzb/zrlog/issues/56