Vulnerability Description
The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability. When any user opens a particular blog hosted on an attackers' site, XSS may occur.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Simple Blog Project | Simple Blog | - |
| Wondercms | Wondercms | 3.4.1 |
Related Weaknesses (CWE)
References
- https://hackerone.com/reports/485748ExploitThird Party Advisory
- https://hackerone.com/reports/647130ExploitThird Party Advisory
- https://hackerone.com/reports/961046ExploitThird Party Advisory
- https://hackerone.com/reports/485748ExploitThird Party Advisory
- https://hackerone.com/reports/647130ExploitThird Party Advisory
- https://hackerone.com/reports/961046ExploitThird Party Advisory
FAQ
What is CVE-2021-42233?
CVE-2021-42233 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability. When any user opens a particular blog hosted on an attackers' site, XSS may occur.
How severe is CVE-2021-42233?
CVE-2021-42233 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-42233?
Check the references section above for vendor advisories and patch information. Affected products include: Simple Blog Project Simple Blog, Wondercms Wondercms.