packetstormsecurity.com
http://packetstormsecurity.com/files/164255/Cloudron-6.2-Cross-Site-Scripting.html CVE-2021-40868
MEDIUMNuclei
Cloudron 6.2 - 'returnTo ' Cross Site Scripting (Reflected)
Record summary
CVE-2021-40868 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBCloudron 6.2 - 'returnTo ' Cross Site Scripting (Reflected)ExploitDB exploitby Akıner KısaNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMCloudron 6.2 Cross-Site ScriptingCVSS 6.1
In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to cross-site scripting.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to potential data theft or unauthorized actions.
Remediation
Upgrade to Cloudron 6.3 or higher.
WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2021cvexsscloudronpacketstormvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:cloudron:cloudron:6.2:*:*:*:*:*:*:*
https://packetstormsecurity.com/files/164255/Cloudron-6.2-Cross-Site-Scripting.html https://nvd.nist.gov/vuln/detail/CVE-2021-40868 https://packetstormsecurity.com/files/164183/Cloudron-6.2-Cross-Site-Scripting.html https://www.cloudron.io/ https://github.com/ARPSyndicate/cvemon
Source: ProjectDiscovery
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-40868 packetstormsecurity.com
https://packetstormsecurity.com/files/164183/Cloudron-6.2-Cross-Site-Scripting.html cloudron.io
https://www.cloudron.io/