CVE-2021-43032: XSS
In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and save an XSS payload in the body of the HTML document. This payload will execute globally on the client side.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-43032?
CVE-2021-43032 has a severity rating that indicates a significant risk due to potential cross-site scripting (XSS) attacks.
How do I fix CVE-2021-43032?
To fix CVE-2021-43032, update your XenForo installation to a version higher than 2.2.7 where the vulnerability has been addressed.
Who can exploit CVE-2021-43032?
CVE-2021-43032 can be exploited by any threat actor with access to the admin panel of XenForo.
What type of vulnerability is CVE-2021-43032?
CVE-2021-43032 is a cross-site scripting (XSS) vulnerability that allows execution of malicious scripts on the client side.
What systems are affected by CVE-2021-43032?
CVE-2021-43032 affects XenForo versions up to and including 2.2.7.