PT-2021-18598 · Mediat · Mediat

Published

2021-05-24

·

Updated

2021-05-28

·

CVE-2021-30083

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mediat version 1.4.1
Description The issue is related to a Reflected XSS vulnerability, which allows remote attackers to inject arbitrary web script or HTML without authentication. This is achieved via the return parameter in the "login.php" endpoint.
Recommendations For Mediat version 1.4.1, consider restricting access to the login.php endpoint or disabling the return parameter to minimize the risk of exploitation until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-30083

Affected Products

Mediat