Vulnerability Description
There is a Cross Site Scripting attack (XSS) vulnerability in JavaQuarkBBS <= v2. By entering specific statements into the background tag management module, the attack statement will be stored in the database, and the next victim will be attacked when he accesses the tag module.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Javaquarkbbs Project | Javaquarkbbs | <= 2 |
Related Weaknesses (CWE)
References
- https://github.com/ChinaLHR/JavaQuarkBBS/issues/23ExploitIssue TrackingThird Party Advisory
- https://github.com/ChinaLHR/JavaQuarkBBS/issues/23ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2021-46030?
CVE-2021-46030 is a vulnerability with a CVSS score of 5.4 (MEDIUM). There is a Cross Site Scripting attack (XSS) vulnerability in JavaQuarkBBS <= v2. By entering specific statements into the background tag management module, the attack statement will be stored in the ...
How severe is CVE-2021-46030?
CVE-2021-46030 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-46030?
Check the references section above for vendor advisories and patch information. Affected products include: Javaquarkbbs Project Javaquarkbbs.