CVE-2021-40868
MEDIUM NUCLEICloudron 6.2 - Reflected Cross-Site Scripting via Login Page returnTo Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-40868. PoCs published by Akıner Kısa. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Cloudron 6.2 via the 'returnTo' parameter in the login page. The attacker can inject malicious JavaScript by appending it to the URL, which executes upon successful login.
Description
In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in Cloudron 6.2 via the 'returnTo' parameter in the login page. The attacker can inject malicious JavaScript by appending it to the URL, which executes upon successful login.
Nuclei Templates (1)
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N