PT-2022-12238 · Unknown · Afi Webacms
Patrick Hener
+1
·
Published
2022-01-20
·
Updated
2022-02-10
·
CVE-2021-44829
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
AFI WebACMS versions through 2.1.0
Description
A Cross Site Scripting (XSS) issue exists in the index.html file of AFI WebACMS via the
ID parameter. This allows for potential malicious script execution.Recommendations
For versions through 2.1.0, consider restricting access to the index.html file or disabling the
ID parameter to minimize the risk of exploitation until a patch is available.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Afi Webacms