CVE-2021-42564

MEDIUM

cryptshare_server < 5.1.0 - Open Redirect via HTML Injection in Confidential Message Editor

Title source: llm
STIX 2.1

Description

An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (with permission to provide confidential messages via Cryptshare) to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' substring in the editor parameter.

References (1)

Core 1
Core References

Scores

CVSS v3 5.4
EPSS 0.0066
EPSS Percentile 46.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-601
Status published
Products (1)
cryptshare/cryptshare_server < 5.1.0
Published Nov 30, 2021
Tracked Since Feb 18, 2026