collabtive.o-dyn.de
https://collabtive.o-dyn.de/forum/viewforum.php?f=6 CVE-2021-3298
MEDIUM
Collabtive 3.1 - 'address' Persistent Cross-Site Scripting
Record summary
CVE-2021-3298 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit.
Description
Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCollabtive 3.1 - 'address' Persistent Cross-Site ScriptingExploitDB exploitby Deha Berkin BirNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-3298 exploit-db.com
https://www.exploit-db.com/exploits/49468