4.8
CVSSv3

CVE-2021-43032

Published: 03/11/2021 Updated: 05/11/2021
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

In XenForo up to and including 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and save an XSS payload in the body of the HTML document. This payload will execute globally on the client side.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xenforo xenforo

Github Repositories

Post authenticated stored-xss in XenForo versions ≤ 2.2.7

CVE-2021-43032 In XenForo ≤ 227, a threat actor with access to the admin panel can save cross-site scripting payloads in any function within the application that accepts HTML code A payload placed within the 'Advertising' functionality will execute globally on the client side, allowing for multiple exploitation scenarios, whereas other payloads will execute on t