PoC Index

CVE-2021-25790

MEDIUM 5.4EPSS 0.9%

Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number.

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
0.88% chance of exploitation in the next 30 days, 57th percentile
Published
2021-07-23
Updated
2024-08-03

Proof-of-concept exploits (2)

References

Related