PT-2021-23309 · Unknown · Justwriting
Seongil-Wio
·
Published
2021-10-01
·
Updated
2021-10-04
·
CVE-2021-41467
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
JustWriting versions 1.0.0 and below
Description
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the
challenge parameter in the application/controllers/dropbox.php file.Recommendations
For JustWriting versions 1.0.0 and below, avoid using the
challenge parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Justwriting