PT-2022-11665 · Unknown · Imprint Cms

CVE-2021-4270

·

Published

2022-12-21

·

Updated

2022-12-27

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Imprint CMS (affected versions not specified)
Description A vulnerability was found in Imprint CMS, classified as problematic. The issue affects the SearchForm function of the file ImprintCMS/Models/ViewHelpers.cs. The manipulation of the query argument leads to cross-site scripting. It is possible to launch the attack remotely.
Recommendations To fix this issue, it is recommended to apply a patch. The name of the patch is 6140b140ccd02b5e4e7d6ba013ac1225724487f4. As a temporary workaround, consider disabling the SearchForm function until a patch is available. Restrict access to the ImprintCMS/Models/ViewHelpers.cs file to minimize the risk of exploitation. Avoid using the query argument in the affected function until the issue is resolved.

Fix

XSS

Improper Neutralization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-4270

Affected Products

Imprint Cms