PoC Index

CVE-2021-43032

MEDIUM 4.8EPSS 0.9%

In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and save an XSS payload in the body of the HTML document. This payload will execute globally on the client side.

CVSS v3.1
4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
0.91% chance of exploitation in the next 30 days, 58th percentile
Published
2021-11-03
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related