CVE-2021-37365 Information

Description

CTparental before 4.45.03 is vulnerable to cross-site scripting (XSS) in the CTparental admin panel. In bl_categires_help.php the ‘categories’ variable is assigned with the content of the query string param ‘cat’ without sanitization or encoding enabling an attacker to inject malicious code into the output webpage.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

https://gist.github.com/securylight/092ba96a660e07ad76f2a380c2eaa75a https://gitlab.com/marsat/CTparental/

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

Share on: