github.com
https://github.com/source-trace/appcms/issues/8 CVE-2021-45380
MEDIUMNuclei
AppCMS - Cross-Site Scripting
Record summary
CVE-2021-45380 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMAppCMS - Cross-Site ScriptingCVSS 6.1
AppCMS 2.0.101 has a cross-site scripting vulnerability in \templates\m\inc_head.php.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
WeaknessesCWE-79
Authorspikpikcu
Template tagscve2021cveappcmsxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:appcms:appcms:2.0.101:*:*:*:*:*:*:*
Shodan: http.html:"Powerd by AppCMS"
Shodan: http.html:"powerd by appcms"
FOFA: body="powerd by appcms"
https://github.com/source-trace/appcms/issues/8 https://nvd.nist.gov/vuln/detail/CVE-2021-45380 https://github.com/ARPSyndicate/cvemon https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-45380