CVE-2021-36454 Information
Description
Cross Site Scripting (XSS) vulnerability in Naviwebs Navigate Cms 2.9 via the navigate-quickse parameter to 1) backups\backups.php 2) blocks\blocks.php 3) brands\brands.php 4) comments\comments.php 5) coupons\coupons.php 6) feeds\feeds.php 7) functions\functions.php 8) items\items.php 9) menus\menus.php 10) orders\orders.php 11) payment_methods\payment_methods.php 12) products\products.php 13) profiles\profiles.php 14) shipping_methods\shipping_methods.php 15) templates\templates.php 16) users\users.php 17) webdictionary\webdictionary.php 18) websites\websites.php and 19) webusers\webusers.php because the initial_url function is built in these files.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
https://github.com/NavigateCMS/Navigate-CMS/issues/24 https://www.navigatecms.com/en/blog/development/navigate_cms_update_2_9_4 Cross Site Scripting (XSS) vulnerability in Naviwebs Navigate Cms 2.9 via the navigate-quickse parameter to 1) backups\backups.php 2) blocks\blocks.php 3) brands\brands.php 4) comments\comments.php 5) coupons\coupons.php 6) feeds\feeds.php 7) functions\functions.php 8) items\items.php 9) menus\menus.php 10) orders\orders.php 11) payment_methods\payment_methods.php 12) products\products.php 13) profiles\profiles.php 14) shipping_methods\shipping_methods.php 15) templates\templates.php 16) users\users.php 17) webdictionary\webdictionary.php 18) websites\websites.php and 19) webusers\webusers.php because the initial_url function is built in these files.
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: