CVE-2021-44911 Information
Jun 07, 2022
cve
Description
XE before 1.11.6 is vulnerable to Unrestricted file upload via modules/menu/menu.admin.controller.php. When uploading the Mouse over button and When selected button there is no restriction on the file suffix which leads to any file uploading to the files directory. Since .htaccess only restricts the PHP type uploading HTML-type files leads to stored XSS vulnerabilities.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
https://github.com/xpressengine/xe-core/issues/2434
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: