PT-2021-20158 · Dutchcoders · Transfer.Sh

Ryotak

·

Published

2021-05-24

·

Updated

2024-08-21

·

CVE-2021-33496

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dutchcoders transfer.sh versions prior to 1.2.4
Description The issue allows cross-site scripting (XSS) via an inline view. This means an attacker could potentially inject malicious scripts into the website, affecting users who access the compromised page.
Recommendations For versions prior to 1.2.4, update to version 1.2.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the inline view feature until the update is applied.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-33496
GHSA-W3JX-WV97-67PH
GO-2022-0924

Affected Products

Transfer.Sh