VDB
CVE-2021-44120
CVE-2021-44120
PUBLISHED
CVSS 5.400000095367432 MEDIUM
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has an article written and available, when a user goes to the public site and wants to read the author's information, the malicious code will be executed. The "Who are you" and "Website Name" fields are vulnerable.
EPSS 0.63% · 47.8th percentile
Risk Scores
CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.63%
47.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| spip | spip | 4.0.0 |
| n/a | n/a | n/a |
Timeline
- Jan 26, 2022 CVE Published
- Jan 27, 2022 EPSS Score
- Feb 1, 2022 CVE Updated
- Mar 21, 2022 EPSS Score
- May 13, 2022 EPSS Score
- Jul 5, 2022 EPSS Score
- Aug 28, 2022 EPSS Score
- Oct 20, 2022 EPSS Score
- Dec 12, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 29, 2023 EPSS Score