Record summary

CVE-2021-42551 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Cross-site Scripting (XSS) vulnerability in the search functionality of AlCoda NetBiblio WebOPAC allows an unauthenticated user to craft a reflected Cross-Site Scripting attack. This issue affects: AlCoda NetBiblio WebOPAC versions prior to 4.0.0.320; versions later than 4.0.0.328. This issue does not affect: AlCoda NetBiblio WebOPAC version 4.0.0.335 and later versions.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListBefore 4.0.0.320affected
next of 4.0.0.328affected
4.0.0.335unaffected

Nuclei templates

1
ProjectDiscoveryMEDIUMNetBiblio WebOPAC - Cross-Site ScriptingCVSS 6.1

NetBiblio WebOPAC before 4.0.0.320 is affected by a reflected cross-site scripting vulnerability in its Wikipedia module through /NetBiblio/search/shortview via the searchTerm parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-79
Authorscompr00t
Template tagscve2021cvexssnetbiblioalcodavuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:alcoda:netbiblio:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2