CVE-2021-33483
Summary
| CVE | CVE-2021-33483 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-07 05:15:00 UTC |
| Updated | 2021-09-13 14:43:00 UTC |
| Description | An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. The comment posting functionality allows an attacker to add an XSS payload to the JSON request that will execute when users visit the page with the comment. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Onyaktech Comments Pro Project | Onyaktech Comments Pro | 3.8 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| OnyakTech (@OnyakTech) | Twitter | MISC | twitter.com | |
| Burninator Sec: OnyakTech Comments Pro - Broken Encryption and XSS CVE-2021-33484 and CVE-2021-33483 | MISC | burninatorsec.blogspot.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.