Record summary

CVE-2021-3355 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit.

Description

A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/SensitiveWords.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBLightCMS 1.3.4 - 'exclusive' Stored XSSExploitDB exploitby PeithonNot analyzed1 file
ExploitDB

PoC details

References

5