CVE-2021-47844
MEDIUMXmind 2020 - Stored Cross-Site Scripting via Malicious Mind Mapping File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47844. PoCs published by TaurusOmar.
AI-analyzed exploit summary This exploit demonstrates an XSS vulnerability in Xmind 2020 that can be leveraged to achieve remote code execution (RCE) via malicious payloads embedded in mind map files. The payloads are encoded to bypass basic filters and execute arbitrary commands when the victim interacts with the file.
Description
Xmind 2020 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into mind mapping files or custom headers. Attackers can craft malicious files with embedded JavaScript that execute system commands when opened, enabling remote code execution through mouse interactions or file opening.
Exploits (1)
This exploit demonstrates an XSS vulnerability in Xmind 2020 that can be leveraged to achieve remote code execution (RCE) via malicious payloads embedded in mind map files. The payloads are encoded to bypass basic filters and execute arbitrary commands when the victim interacts with the file.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N