CVE-2021-44082
Summary
| CVE | CVE-2021-44082 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-29 23:15:00 UTC |
| Updated | 2022-04-06 18:41:00 UTC |
| Description | textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by uploading a webshell. To do so they must first steal the CSRF token before submitting a file upload request. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 730415 Textpattern CMS Cross-Site Scripting (XSS) Vulnerability