PT-2021-22582 · Seo Panel · Seo Panel
Published
2021-11-05
·
Updated
2024-03-06
·
CVE-2021-39413
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
SEO Panel version 4.8.0
Description:
Multiple Cross Site Scripting (XSS) vulnerabilities exist in SEO Panel via several parameters in various PHP files. The affected parameters include
to time in files such as backlinks.php, analytics.php, and log.php, from time in files like backlinks.php, analytics.php, and webmaster-tools.php, order col in files such as analytics.php and review.php, and pageno in files like alerts.php and log.php.Recommendations:
For SEO Panel version 4.8.0, consider disabling the
to time, from time, order col, and pageno parameters in the affected PHP files until a patch is available. Restrict access to the vulnerable PHP files, such as backlinks.php, analytics.php, and log.php, to minimize the risk of exploitation. Avoid using the to time, from time, order col, and pageno parameters in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Seo Panel