Record summary

CVE-2021-40868 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBCloudron 6.2 - 'returnTo ' Cross Site Scripting (Reflected)ExploitDB exploitby Akıner KısaNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMCloudron 6.2 Cross-Site ScriptingCVSS 6.1

In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to cross-site scripting.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to potential data theft or unauthorized actions.

Remediation

Upgrade to Cloudron 6.3 or higher.

WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2021cvexsscloudronpacketstormvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:cloudron:cloudron:6.2:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

4