CVE-2021-42551
Reflected XSS in NetBiblio WebOPAC search functionality
Record summary
CVE-2021-42551 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Cross-site Scripting (XSS) vulnerability in the search functionality of AlCoda NetBiblio WebOPAC allows an unauthenticated user to craft a reflected Cross-Site Scripting attack. This issue affects: AlCoda NetBiblio WebOPAC versions prior to 4.0.0.320; versions later than 4.0.0.328. This issue does not affect: AlCoda NetBiblio WebOPAC version 4.0.0.335 and later versions.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
NetBiblio WebOPACBrowse AlCoda / NetBiblio WebOPAC | CVE List | Before 4.0.0.320 | affected |
| next of 4.0.0.328 | affected | ||
| 4.0.0.335 | unaffected |
Nuclei templates
1ProjectDiscoveryMEDIUMNetBiblio WebOPAC - Cross-Site ScriptingCVSS 6.1
NetBiblio WebOPAC before 4.0.0.320 is affected by a reflected cross-site scripting vulnerability in its Wikipedia module through /NetBiblio/search/shortview via the searchTerm parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
Source: ProjectDiscovery