A cross-site scripting (XSS) vulnerability in many forms of Wikindx before 5.7.0 and 6.x through 6.4.0 allows remote attackers to inject arbitrary web script or HTML via the message parameter to index.php?action=initLogon or modules/admin/DELETEIMAGES.php.
References
Link | Resource |
---|---|
https://sourceforge.net/p/wikindx/news/2021/01/wikindx-v641-released/ | Release Notes Third Party Advisory |
https://sourceforge.net/projects/wikindx/ | Product Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2021-02-01 22:15
Updated : 2021-02-04 18:10
NVD link : CVE-2021-3340
Mitre link : CVE-2021-3340
CVE.ORG link : CVE-2021-3340
JSON object : View
Products Affected
wikindx_project
- wikindx
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')