ZeroHour

CVE-2021-37271

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p45
Published
()
Modified
Description

Cross Site Scripting (XSS) vulnerability exists in UEditor v1.4.3.3, which can be exploited by an attacker to obtain user cookie information.

Vendors
baidu
Products
ueditor
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.