Vulnerability Description
YouPHPTube <= 7.8 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the redirectUri parameter in the signup page. Attackers can craft special signup URLs with embedded script tags to execute arbitrary JavaScript in victims' browsers when they access the signup page.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Youphptube | Youphptube | <= 7.8 |
Related Weaknesses (CWE)
References
- https://web.archive.org/web/20170506141644/https://www.youphptube.com/Not Applicable
- https://www.exploit-db.com/exploits/51101ExploitThird Party AdvisoryVDB Entry
- https://www.vulncheck.com/advisories/youphptube-cross-site-scriptingThird Party Advisory
FAQ
What is CVE-2021-47750?
CVE-2021-47750 is a vulnerability with a CVSS score of 6.1 (MEDIUM). YouPHPTube <= 7.8 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the redirectUri parameter in the signup page. Attackers can craft special sign...
How severe is CVE-2021-47750?
CVE-2021-47750 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-47750?
Check the references section above for vendor advisories and patch information. Affected products include: Youphptube Youphptube.