Vulnerability Description
thinkphp-bjyblog (last update Jun 4 2021) is affected by a Cross Site Scripting (XSS) vulnerability in AdminBaseController.class.php. The exit function terminates the script and prints a message to the user that contains $_SERVER['HTTP_HOST'].
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Thinkphp-Bjyblog Project | Thinkphp-Bjyblog | - |
Related Weaknesses (CWE)
References
- https://github.com/baijunyao/thinkphp-bjyblog/issues/6ExploitIssue TrackingThird Party Advisory
- https://github.com/baijunyao/thinkphp-bjyblog/issues/6ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2021-43682?
CVE-2021-43682 is a vulnerability with a CVSS score of 6.1 (MEDIUM). thinkphp-bjyblog (last update Jun 4 2021) is affected by a Cross Site Scripting (XSS) vulnerability in AdminBaseController.class.php. The exit function terminates the script and prints a message to th...
How severe is CVE-2021-43682?
CVE-2021-43682 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-43682?
Check the references section above for vendor advisories and patch information. Affected products include: Thinkphp-Bjyblog Project Thinkphp-Bjyblog.