PT-2021-4000 · Sourcecodester · Sourcecodester Fantastic Blog Cms
Published
2021-01-21
·
Updated
2021-07-30
·
CVE-2021-26224
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SourceCodester Fantastic-Blog-CMS version 1.0
Description
The issue is related to a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the search field in the search.php script, potentially enabling an attacker to perform cross-site scripting attacks.
Recommendations
For SourceCodester Fantastic-Blog-CMS version 1.0, consider restricting access to the search field in search.php until a patch is available. As a temporary workaround, avoid using the search functionality in the affected version to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Fantastic Blog Cms