In Factor (App Framework & Headless CMS) forum plugin, versions v1.3.8 to v1.8.30, are vulnerable to reflected Cross-Site Scripting (XSS) at the “tags” and “category” parameters in the URL. An unauthenticated attacker can execute malicious JavaScript code and steal the session cookies.
                
            References
                    Configurations
                    History
                    No history.
Information
                Published : 2021-11-16 10:15
Updated : 2024-11-21 05:55
NVD link : CVE-2021-25983
Mitre link : CVE-2021-25983
CVE.ORG link : CVE-2021-25983
JSON object : View
Products Affected
                darwin
- factor
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
