{"api_version":"1","generated_at":"2026-07-23T15:35:27+00:00","cve":"CVE-2021-33483","urls":{"html":"https://cve.report/CVE-2021-33483","api":"https://cve.report/api/cve/CVE-2021-33483.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-33483","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-33483"},"summary":{"title":"CVE-2021-33483","description":"An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. The comment posting functionality allows an attacker to add an XSS payload to the JSON request that will execute when users visit the page with the comment.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-09-07 05:15:00","updated_at":"2021-09-13 14:43:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://twitter.com/onyaktech","name":"https://twitter.com/onyaktech","refsource":"MISC","tags":[],"title":"OnyakTech (@OnyakTech) | Twitter","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://burninatorsec.blogspot.com/2021/07/onyaktech-comments-pro-broken.html","name":"https://burninatorsec.blogspot.com/2021/07/onyaktech-comments-pro-broken.html","refsource":"MISC","tags":[],"title":"Burninator Sec: OnyakTech Comments Pro - Broken Encryption and XSS CVE-2021-33484 and CVE-2021-33483","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-33483","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-33483","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"33483","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"onyaktech_comments_pro_project","cpe5":"onyaktech_comments_pro","cpe6":"3.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-33483","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. The comment posting functionality allows an attacker to add an XSS payload to the JSON request that will execute when users visit the page with the comment."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://twitter.com/onyaktech","refsource":"MISC","name":"https://twitter.com/onyaktech"},{"refsource":"MISC","name":"https://burninatorsec.blogspot.com/2021/07/onyaktech-comments-pro-broken.html","url":"https://burninatorsec.blogspot.com/2021/07/onyaktech-comments-pro-broken.html"}]}},"nvd":{"publishedDate":"2021-09-07 05:15:00","lastModifiedDate":"2021-09-13 14:43:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:onyaktech_comments_pro_project:onyaktech_comments_pro:3.8:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"33483","Ordinal":"208888","Title":"CVE-2021-33483","CVE":"CVE-2021-33483","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"33483","Ordinal":"1","NoteData":"An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. The comment posting functionality allows an attacker to add an XSS payload to the JSON request that will execute when users visit the page with the comment.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"33483","Ordinal":"2","NoteData":"2021-09-07","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"33483","Ordinal":"3","NoteData":"2021-09-07","Type":"Other","Title":"Modified"}]}}}