Vulnerability Description
In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and save an XSS payload in the body of the HTML document. This payload will execute globally on the client side.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xenforo | Xenforo | <= 2.2.7 |
Related Weaknesses (CWE)
References
- https://github.com/SakuraSamuraii/CVE-2021-43032ExploitThird Party Advisory
- https://xenforo.com/community/forums/announcements/Release NotesVendor Advisory
- https://github.com/SakuraSamuraii/CVE-2021-43032ExploitThird Party Advisory
- https://xenforo.com/community/forums/announcements/Release NotesVendor Advisory
FAQ
What is CVE-2021-43032?
CVE-2021-43032 is a vulnerability with a CVSS score of 4.8 (MEDIUM). In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and save an XSS payload in the body of the HTML document. This payl...
How severe is CVE-2021-43032?
CVE-2021-43032 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-43032?
Check the references section above for vendor advisories and patch information. Affected products include: Xenforo Xenforo.