github.com
https://github.com/gnuboard/gnuboard5/commit/2e81619ea87bc9c0b4a073d8df3c7693a6fdbf0d CVE-2021-3831
MEDIUMNuclei
Cross-site Scripting (XSS) - Reflected in gnuboard/gnuboard5
Record summary
CVE-2021-3831 has a selected CVSS score of 6.1 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
gnuboard/gnuboard5Browse gnuboard / gnuboard/gnuboard5 | CVE List | Before 5.4.20 | affected |
Proofs of concept
1Repository PoCs
GitHubaratane/CVE-2021-3831Repository PoCby arataneStars: 0Not analyzed2 files
Nuclei templates
1ProjectDiscoveryMEDIUMGnuboard 5 - Cross-Site ScriptingCVSS 5.4
Gnuboard 5 contains a cross-site scripting vulnerability via the $_GET['LGD_OID'] parameter.
Impact
Attackers can inject malicious JavaScript via XSS in the LGD_OID parameter, potentially stealing user session cookies or performing unauthorized actions.
Remediation
Apply security patches or upgrade to a patched version of Gnuboard 5.
WeaknessesCWE-80
Authorsarafatansari
Template tagscvecve2021gnuboardxsshuntrvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:gnuboard:gnuboard5:*:*:*:*:*:*:*:*
Shodan: http.html:"gnuboard5"
https://huntr.dev/bounties/ed317cde-9bd1-429e-b6d3-547e72534dd5/ https://vulners.com/huntr/25775287-88CD-4F00-B978-692D627DFF04 https://nvd.nist.gov/vuln/detail/CVE-2021-3831
Source: ProjectDiscovery
References
3huntr.devConfirmation
https://huntr.dev/bounties/25775287-88cd-4f00-b978-692d627dff04 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-3831