CVE-2021-36454
Published on: 08/06/2021 12:00:00 AM UTC
Last Modified on: 08/12/2021 08:11:00 PM UTC
Certain versions of Navigate Cms from Naviwebs contain the following vulnerability:
Cross Site Scripting (XSS) vulnerability in Naviwebs Navigate Cms 2.9 via the navigate-quickse parameter to 1) backups\backups.php, 2) blocks\blocks.php, 3) brands\brands.php, 4) comments\comments.php, 5) coupons\coupons.php, 6) feeds\feeds.php, 7) functions\functions.php, 8) items\items.php, 9) menus\menus.php, 10) orders\orders.php, 11) payment_methods\payment_methods.php, 12) products\products.php, 13) profiles\profiles.php, 14) shipping_methods\shipping_methods.php, 15) templates\templates.php, 16) users\users.php, 17) webdictionary\webdictionary.php, 18) websites\websites.php, and 19) webusers\webusers.php because the initial_url function is built in these files.
- CVE-2021-36454 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 5.4 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | NONE |
CVSS2 Score: 3.5 - LOW
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | PARTIAL | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Reflected XSS attack with navigate-quickse parameter and affect many modules in NavigateCMS 2.9 · Issue #24 · NavigateCMS/Navigate-CMS · GitHub | github.com text/html |
![]() |
Navigate CMS | Navigate CMS Update: 2.9.4 | www.navigatecms.com text/html |
![]() |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Naviwebs | Navigate Cms | 2.9 | All | All | All |
- cpe:2.3:a:naviwebs:navigate_cms:2.9:*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-36454 : Cross Site Scripting #XSS vulnerability in Naviwebs Navigate Cms 2.9 via the navigate-quickse pa… twitter.com/i/web/status/1… | 2021-08-06 16:08:56 |
![]() |
Php - CVE-2021-36454: github.com/NavigateCMS/Na… | 2021-08-06 18:30:31 |