Record summary

CVE-2021-3002 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Seo Panel 4.8.0 allows reflected XSS via the seo/seopanel/login.php?sec=forgot email parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMSeo Panel 4.8.0 - Cross-Site ScriptingCVSS 6.1

Seo Panel 4.8.0 contains a reflected cross-site scripting vulnerability via the seo/seopanel/login.php?sec=forgot email parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement of the affected website.

Remediation

Upgrade to a patched version of Seo Panel or apply the necessary security patches provided by the vendor.

WeaknessesCWE-79
Authorsedoardottt
Template tagscve2021cveseopanelxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:seopanel:seo_panel:4.8.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3