ZeroHour

CVE-2021-3395

CVSS 3.1
5.4 medium
EPSS
<1%p53
Published
()
Modified
Description

A cross-site scripting (XSS) vulnerability in Pryaniki 6.44.3 allows remote authenticated users to upload an arbitrary file. The JavaScript code will execute when someone visits the attachment.

Vendors
pryaniki
Products
pryaniki
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.