ZeroHour

CVE-2021-33483

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p48
Published
()
Modified
Description

An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. The comment posting functionality allows an attacker to add an XSS payload to the JSON request that will execute when users visit the page with the comment.

Vendors
onyaktech comments pro project
Products
onyaktech comments pro
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.