CVE-2021-27308
MEDIUM4images <1.8 - XSS
Title source: llmDescription
A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the "redirect" parameter.
Exploits (1)
Scores
CVSS v3
4.8
EPSS
0.0047
EPSS Percentile
64.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
4homepages/4images
1.8
Published
Mar 22, 2021
Tracked Since
Feb 18, 2026