CVE-2021-26549
Summary
| CVE | CVE-2021-26549 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-09 20:15:00 UTC |
| Updated | 2021-02-16 17:11:00 UTC |
| Description | An XSS issue was discovered in SmartFoxServer 2.17.0. Input passed to the AdminTool console is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML code in a user's browser session in context of an affected site. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Smartfoxserver | Smartfoxserver | 2.17.0 | All | All | All |
| Application | Smartfoxserver | Smartfoxserver | 2.17.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.smartfoxserver.com | MISC | www.smartfoxserver.com | Product |
| Zero Science Lab » SmartFoxServer 2X 2.17.0 God Mode Console WebSocket XSS | MISC | www.zeroscience.mk | Exploit, Third Party Advisory |
| SmartFoxServer 2X 2.17.0 God Mode Console WebSocket Cross Site Scripting ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| Zero Science Lab | MISC | www.zeroscience.mk | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.