ZeroHour

CVE-2021-43032

PoC
CVSS 3.1
4.8 medium
EPSS
<1%p58
Published
()
Modified
Description

In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and save an XSS payload in the body of the HTML document. This payload will execute globally on the client side.

Vendors
xenforo
Products
xenforo
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.