CVE-2021-39391
Summary
| CVE | CVE-2021-39391 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-14 18:15:00 UTC |
| Updated | 2021-09-24 18:49:00 UTC |
| Description | Cross Site Scripting (XSS) vulnerability exists in the admin panel in Beego v2.0.1 via the URI path in an HTTP request, which is activated by administrators viewing the "Request Statistics" page. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| XSS in Admin Panel · Issue #4727 · beego/beego · GitHub | MISC | github.com | |
| GitHub - beego/beego: beego is an open-source, high-performance web framework for the Go programming language. | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980497 Go (go) Security Update for github.com/beego/beego/v2 (GHSA-c77f-4rgj-jfr4)