CVE-2021-37392 Information

Description

In RPCMS v1.8 and below the ickname\ variable is not properly sanitized before being displayed on page. When the API functions are enabled the attacker can use API to update user nickname with XSS payload and achieve stored XSS. Users who view the articles published by the injected user will trigger the XSS.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Reference

https://github.com/ralap-z/RPCMS/ https://gist.github.com/victomteng1997/bfa1e0e07dd22f7e0b13256eda79626f

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

5.4

Share on: