CVE-2021-32106: XSS
In ICEcoder 8.0 allows, a reflected XSS vulnerability was identified in the multipe-results.php page due to insufficient sanitization of the GET['replace'] variable. As a result, arbitrary Javascript code can get executed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32106?
The severity of CVE-2021-32106 is medium with a CVSS score of 5.4.
How does the XSS vulnerability in CVE-2021-32106 occur?
The XSS vulnerability in CVE-2021-32106 occurs due to insufficient sanitization of the _GET['replace'] variable in the multipe-results.php page of ICEcoder 8.0.
What is the impact of the XSS vulnerability in CVE-2021-32106?
The XSS vulnerability in CVE-2021-32106 allows arbitrary JavaScript code to be executed, posing a risk of unauthorized access or data theft.
What is the affected software version of CVE-2021-32106?
The affected software version of CVE-2021-32106 is ICEcoder 8.0.
Are there any references related to CVE-2021-32106?
Yes, you can find more information about CVE-2021-32106 in the following references: [Link 1](https://github.com/icecoder/ICEcoder), [Link 2](https://groups.google.com/g/icecoder/c/xcAc8_1UPxQ), [Link 3](https://prophaze.com/cve/icecoder-8-0-multipe-results-php-replace-cross-site-scripting/)