Vulnerability Description
A cross-site scripting vulnerability is present in Xbtit 3.1. The stored XSS vulnerability occurs because /ajaxchat/sendChatData.php does not properly validate the value of the "n" (POST) parameter. Through this vulnerability, an attacker is capable to execute malicious JavaScript code.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Btiteam | Xbtit | 3.1 |
Related Weaknesses (CWE)
References
- https://emaragkos.gr/infosec-adventures/xbtit-3-1-xss-stored-amp-reflected/ExploitThird Party Advisory
- https://github.com/btiteam/xbtit-3.1Third Party Advisory
- https://github.com/btiteam/xbtit-3.1/issues/7ExploitThird Party Advisory
- https://emaragkos.gr/infosec-adventures/xbtit-3-1-xss-stored-amp-reflected/ExploitThird Party Advisory
- https://github.com/btiteam/xbtit-3.1Third Party Advisory
- https://github.com/btiteam/xbtit-3.1/issues/7ExploitThird Party Advisory
FAQ
What is CVE-2021-45822?
CVE-2021-45822 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A cross-site scripting vulnerability is present in Xbtit 3.1. The stored XSS vulnerability occurs because /ajaxchat/sendChatData.php does not properly validate the value of the "n" (POST) parameter. T...
How severe is CVE-2021-45822?
CVE-2021-45822 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-45822?
Check the references section above for vendor advisories and patch information. Affected products include: Btiteam Xbtit.