cinquino.eu
http://www.cinquino.eu/SeoPanelReflect.htm CVE-2021-3002
MEDIUMNuclei
Seo Panel 4.8.0 - Cross-Site Scripting
Record summary
CVE-2021-3002 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Seo Panel 4.8.0 allows reflected XSS via the seo/seopanel/login.php?sec=forgot email parameter.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMSeo Panel 4.8.0 - Cross-Site ScriptingCVSS 6.1
Seo Panel 4.8.0 contains a reflected cross-site scripting vulnerability via the seo/seopanel/login.php?sec=forgot email parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement of the affected website.
Remediation
Upgrade to a patched version of Seo Panel or apply the necessary security patches provided by the vendor.
WeaknessesCWE-79
Authorsedoardottt
Template tagscve2021cveseopanelxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:seopanel:seo_panel:4.8.0:*:*:*:*:*:*:*
http://www.cinquino.eu/SeoPanelReflect.htm https://github.com/seopanel/Seo-Panel/issues/202 https://nvd.nist.gov/vuln/detail/CVE-2021-3002 https://github.com/ARPSyndicate/kenzer-templates https://github.com/ArrestX/--POC
Source: ProjectDiscovery
References
3github.com
https://github.com/seopanel/Seo-Panel/issues/202 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-3002