{"api_version":"1","generated_at":"2026-07-24T00:33:22+00:00","cve":"CVE-2021-39391","urls":{"html":"https://cve.report/CVE-2021-39391","api":"https://cve.report/api/cve/CVE-2021-39391.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-39391","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-39391"},"summary":{"title":"CVE-2021-39391","description":"Cross Site Scripting (XSS) vulnerability exists in the admin panel in Beego v2.0.1 via the URI path in an HTTP request, which is activated by administrators viewing the \"Request Statistics\" page.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-09-14 18:15:00","updated_at":"2021-09-24 18:49:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://github.com/beego/beego/issues/4727","name":"https://github.com/beego/beego/issues/4727","refsource":"MISC","tags":[],"title":"XSS in Admin Panel · Issue #4727 · beego/beego · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/beego/beego","name":"https://github.com/beego/beego","refsource":"MISC","tags":[],"title":"GitHub - beego/beego: beego is an open-source, high-performance web framework for the Go programming language.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-39391","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-39391","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"39391","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"beego","cpe5":"beego","cpe6":"2.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-39391","qid":"980497","title":"Go (go) Security Update for github.com/beego/beego/v2 (GHSA-c77f-4rgj-jfr4)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-39391","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross Site Scripting (XSS) vulnerability exists in the admin panel in Beego v2.0.1 via the URI path in an HTTP request, which is activated by administrators viewing the \"Request Statistics\" page."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/beego/beego","refsource":"MISC","name":"https://github.com/beego/beego"},{"url":"https://github.com/beego/beego/issues/4727","refsource":"MISC","name":"https://github.com/beego/beego/issues/4727"}]}},"nvd":{"publishedDate":"2021-09-14 18:15:00","lastModifiedDate":"2021-09-24 18:49:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:beego:beego:2.0.1:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"39391","Ordinal":"215095","Title":"CVE-2021-39391","CVE":"CVE-2021-39391","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"39391","Ordinal":"1","NoteData":"Cross Site Scripting (XSS) vulnerability exists in the admin panel in Beego v2.0.1 via the URI path in an HTTP request, which is activated by administrators viewing the \"Request Statistics\" page.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"39391","Ordinal":"2","NoteData":"2021-09-14","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"39391","Ordinal":"3","NoteData":"2021-09-14","Type":"Other","Title":"Modified"}]}}}