5.4

CVE-2021-45787

Exploit
There is a stored Cross Site Scripting (XSS) vulnerability in maccms v10 through adding videos. XSS code can be inserted at parameter positions including name and remarks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MaccmsMaccms Version10.0 Update-
MaccmsMaccms Version10.0 Update2018.03.15
MaccmsMaccms Version10.0 Update2018.03.21
MaccmsMaccms Version10.0 Update2018.04.02
MaccmsMaccms Version10.0 Update2018.05.01
MaccmsMaccms Version10.0 Update2018.05.02.1005
MaccmsMaccms Version10.0 Update2018.05.03.0000
MaccmsMaccms Version10.0 Update2018.05.04.1320
MaccmsMaccms Version10.0 Update2018.05.07.1213
MaccmsMaccms Version10.0 Update2018.05.08.2020
MaccmsMaccms Version10.0 Update2018.05.09.1320
MaccmsMaccms Version10.0 Update2018.05.11.2300
MaccmsMaccms Version10.0 Update2018.05.15.1403
MaccmsMaccms Version10.0 Update2018.05.17.1050
MaccmsMaccms Version10.0 Update2018.05.22.1338
MaccmsMaccms Version10.0 Update2018.05.30.1007
MaccmsMaccms Version10.0 Update2018.06.04.1510
MaccmsMaccms Version10.0 Update2018.06.08.1339
MaccmsMaccms Version10.0 Update2018.06.12.1430
MaccmsMaccms Version10.0 Update2018.06.15.0910
MaccmsMaccms Version10.0 Update2018.06.29.1425
MaccmsMaccms Version10.0 Update2018.07.29.1010
MaccmsMaccms Version10.0 Update2018.08.14.0955
MaccmsMaccms Version10.0 Update2018.08.24.1355
MaccmsMaccms Version10.0 Update2018.08.25.1120
MaccmsMaccms Version10.0 Update2018.09.03.0920
MaccmsMaccms Version10.0 Update2018.09.14.0850
MaccmsMaccms Version10.0 Update2018.09.28.0950
MaccmsMaccms Version10.0 Update2018.10.09.1333
MaccmsMaccms Version10.0 Update2018.10.13.1025
MaccmsMaccms Version10.0 Update2018.10.22.1200
MaccmsMaccms Version10.0 Update2018.10.31.1340
MaccmsMaccms Version10.0 Update2018.11.18.0920
MaccmsMaccms Version10.0 Update2018.12.05.0950
MaccmsMaccms Version10.0 Update2018.12.13.2151
MaccmsMaccms Version10.0 Update2019.00.00.1001
MaccmsMaccms Version10.0 Update2019.00.00.1002
MaccmsMaccms Version10.0 Update2019.00.00.1003
MaccmsMaccms Version10.0 Update2019.00.00.1004
MaccmsMaccms Version10.0 Update2019.00.00.1005
MaccmsMaccms Version10.0 Update2019.00.00.1006
MaccmsMaccms Version10.0 Update2019.00.00.1007
MaccmsMaccms Version10.0 Update2019.00.00.1008
MaccmsMaccms Version10.0 Update2019.01.19.1001
MaccmsMaccms Version10.0 Update2019.0101.1001
MaccmsMaccms Version10.0 Update2019.02.23.0850
MaccmsMaccms Version10.0 Update2019.03.06.1617
MaccmsMaccms Version10.0 Update2019.1000.1009
MaccmsMaccms Version10.0 Update2019.1000.1010
MaccmsMaccms Version10.0 Update2019.1000.1011
MaccmsMaccms Version10.0 Update2019.1000.1012
MaccmsMaccms Version10.0 Update2019.1000.1013
MaccmsMaccms Version10.0 Update2019.1000.1014
MaccmsMaccms Version10.0 Update2019.1000.1015
MaccmsMaccms Version10.0 Update2019.1000.1016
MaccmsMaccms Version10.0 Update2019.1000.1017
MaccmsMaccms Version10.0 Update2019.1000.1018
MaccmsMaccms Version10.0 Update2020.1000.1019
MaccmsMaccms Version10.0 Update2020.1000.1020
MaccmsMaccms Version10.0 Update2020.1000.1021
MaccmsMaccms Version10.0 Update2020.1000.1022
MaccmsMaccms Version10.0 Update2020.1000.1023
MaccmsMaccms Version10.0 Update2020.1000.1024
MaccmsMaccms Version10.0 Update2020.1000.1025
MaccmsMaccms Version10.0 Update2020.1000.1027
MaccmsMaccms Version10.0 Update2020.1000.1029
MaccmsMaccms Version10.0 Update2020.1000.1031
MaccmsMaccms Version10.0 Update2020.1000.1032
MaccmsMaccms Version10.0 Update2020.1000.1033
MaccmsMaccms Version10.0 Update2020.1000.1034
MaccmsMaccms Version10.0 Update2020.1000.1035
MaccmsMaccms Version10.0 Update2020.1000.1039
MaccmsMaccms Version10.0 Update2020.1000.1042
MaccmsMaccms Version10.0 Update2020.1000.1051
MaccmsMaccms Version10.0 Update2020.1000.1060
MaccmsMaccms Version10.0 Update2020.1000.1062
MaccmsMaccms Version10.0 Update2020.1000.1068
MaccmsMaccms Version10.0 Update2020.1000.1068b
MaccmsMaccms Version10.0 Update2020.1000.1069
MaccmsMaccms Version10.0 Update2020.1000.1074
MaccmsMaccms Version10.0 Update2020.1000.1075
MaccmsMaccms Version10.0 Update2020.1000.1080
MaccmsMaccms Version10.0 Update2020.1000.1081
MaccmsMaccms Version10.0 Update2021.1000.1081
MaccmsMaccms Version10.0 Update2022.1000.1099
MaccmsMaccms Version10.0 Update2022.1000.3001
MaccmsMaccms Version10.0 Update2022.1000.3002
MaccmsMaccms Version10.0 Update2022.1000.3004
MaccmsMaccms Version10.0 Update2022.1000.3005
MaccmsMaccms Version10.0 Update2022.1000.3025
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.413
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.