CVE-2021-30071: XSS
A cross-site scripting (XSS) vulnerability in /admin/listkey.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-30071?
The severity of CVE-2021-30071 is medium, with a severity value of 6.1.
How does the cross-site scripting (XSS) vulnerability in CVE-2021-30071 work?
The cross-site scripting (XSS) vulnerability in CVE-2021-30071 allows attackers to execute arbitrary web scripts or HTML by exploiting a vulnerability in /admin/list_key.html of HestiaCP before v1.3.5.
Who is affected by CVE-2021-30071?
Users of HestiaCP before v1.3.5 are affected by CVE-2021-30071.
Is there a fix available for CVE-2021-30071?
Yes, a fix for CVE-2021-30071 is available in HestiaCP v1.3.5 or later. It is recommended to update to the latest version.
What is the Common Weakness Enumeration (CWE) for CVE-2021-30071?
The Common Weakness Enumeration (CWE) for CVE-2021-30071 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').