PT-2021-20912 · Smashing · Smashing
Gebhardtr
·
Published
2021-07-06
·
Updated
2022-05-24
·
CVE-2021-35440
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Smashing version 1.3.4
Description:
The issue allows an attacker to craft a URL for a widget that can execute JavaScript on the victim's computer, potentially stealing data available in the session or cookies, especially in environments where internal URLs are reused or cookies have permissive settings.
Recommendations:
For Smashing version 1.3.4, consider disabling the execution of JavaScript code from crafted widget URLs as a temporary workaround until a patch is available. Restrict access to sensitive session data and cookies to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smashing