cve/2021/CVE-2021-25982.md
2024-06-18 02:51:15 +02:00

823 B

CVE-2021-25982

Description

In Factor (App Framework & Headless CMS) forum plugin, versions 1.3.5 to 1.8.30, are vulnerable to reflected Cross-Site Scripting (XSS) at the “search” parameter in the URL. An unauthenticated attacker can execute malicious JavaScript code and steal the session cookies.

POC

Reference

Github

No PoCs found on GitHub currently.