CVE-2021-4266
Webdetails cpf DependenciesPackage.java cross site scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability classified as problematic has been found in Webdetails cpf up to 9.5.0.0-80. Affected is an unknown function of the file core/src/main/java/pt/webdetails/cpf/packager/DependenciesPackage.java. The manipulation of the argument baseUrl leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 9.5.0.0-81 is able to address this issue. The name of the patch is 3bff900d228e8cae3af256b447c5d15bdb03c174. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216468.
Una vulnerabilidad ha sido encontrada en Webdetails cpf hasta 9.5.0.0-80 y clasificada como problemática. Una función desconocida del archivo core/src/main/java/pt/webdetails/cpf/packager/DependenciesPackage.java es afectada por esta función. La manipulación del argumento baseUrl conduce a Cross-Site Scripting. Es posible lanzar el ataque de forma remota. La actualización a la versión 9.5.0.0-81 puede solucionar este problema. El nombre del parche es 3bff900d228e8cae3af256b447c5d15bdb03c174. Se recomienda actualizar el componente afectado. El identificador de esta vulnerabilidad es VDB-216468.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-12-21 CVE Reserved
- 2022-12-21 CVE Published
- 2024-07-13 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-707: Improper Neutralization
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/siwapp/siwapp-ror/pull/365 | Not Applicable | |
https://github.com/webdetails/cpf/releases/tag/9.5.0.0-81 | Release Notes | |
https://vuldb.com/?id.216468 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/webdetails/cpf/commit/3bff900d228e8cae3af256b447c5d15bdb03c174 | 2023-11-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hitachi Search vendor "Hitachi" | Community Plugin Framework Search vendor "Hitachi" for product "Community Plugin Framework" | < 9.5.0.0-81 Search vendor "Hitachi" for product "Community Plugin Framework" and version " < 9.5.0.0-81" | - |
Affected
|