PoC Index

CVE-2021-35488

MEDIUM 6.1EPSS 2.6%

Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title parameter. An attacker could inject arbitrary JavaScript into status.cgi. The payload would be triggered every time an authenticated user browses the page containing it.

CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
2.63% chance of exploitation in the next 30 days, 84th percentile
Nuclei
medium · CWE-79
Published
2021-11-09
Updated
2024-08-04

Nuclei templates (1)

References

Related