CVE-2021-43725
Spotweb <= 1.5.1 - Cross Site Scripting (Reflected)
Record summary
CVE-2021-43725 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web script or HTML via the data[performredirect] parameter.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMSpotweb <= 1.5.1 - Cross Site Scripting (Reflected)CVSS 6.1
There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web script or HTML via the data[performredirect] parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the victim's browser, potentially leading to session hijacking, data theft, or other attacks.
Remediation
Fixed in version 1.5.2
Source: ProjectDiscovery