CVE-2021-43673: XSS
Published Dec 3, 2021
·Updated
dzzoffice 2.02.1SCUTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php. The output of the exit function is printed for the user via exit(jsonencode($return)).
Affected Software
1 affected component
dzzoffice DzzOffice=2.02.1
Event History
Dec 3, 2021
CVE Published
via MITRE·11:36 AM
Data Sourced
via MITRE·11:36 AM
Description
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-43673?
CVE-2021-43673 is a Cross Site Scripting (XSS) vulnerability in dzzoffice version 2.02.1_SC_UTF8.
2
How does CVE-2021-43673 affect dzzoffice?
CVE-2021-43673 affects dzzoffice 2.02.1_SC_UTF8 by allowing an attacker to execute malicious scripts on a user's browser.
3
What is the severity level of CVE-2021-43673?
The severity level of CVE-2021-43673 is medium with a CVSS score of 6.1.
4
How can I fix the CVE-2021-43673 vulnerability?
To fix the CVE-2021-43673 vulnerability, update dzzoffice to a version that includes the necessary security patches.
5
Where can I find more information about CVE-2021-43673?
You can find more information about CVE-2021-43673 at the following reference: https://github.com/zyx0814/dzzoffice/issues/188