PT-2021-10608 · Zrlog · Zrlog

T-Podo

·

Published

2021-06-15

·

Updated

2021-06-22

·

CVE-2020-21316

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: ZrLog version 2.1.3
Description: A Cross-site scripting (XSS) vulnerability exists in the comment section, which allows remote attackers to inject arbitrary web script and steal administrator cookies via the nickname parameter, gaining access to the admin panel.
Recommendations: For ZrLog version 2.1.3, consider disabling the comment section or restricting access to it until a patch is available to prevent exploitation of the XSS vulnerability. Avoid using the nickname parameter in the comment section until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-21316

Affected Products

Zrlog