Description
A cross-site scripting (XSS) vulnerability in Pryaniki 6.44.3 allows remote authenticated users to upload an arbitrary file. The JavaScript code will execute when someone visits the attachment.
Exploits (1)
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://github.com/jet-pentest/CVE-2021-3395/
Product, Vendor Advisory x_refsource_misc
https://pryaniky.com/en/home/
Scores
CVSS v3
5.4
EPSS
0.0023
EPSS Percentile
45.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
pryaniki/pryaniki
6.44.3
Published
Feb 02, 2021
Tracked Since
Feb 18, 2026