CVE-2021-44584: XSS
Published Jan 6, 2022
·Updated
Cross-site scripting (XSS) vulnerability in index.php in emlog version <= pro-1.0.7 allows remote attackers to inject arbitrary web script or HTML via the s parameter.
Affected Software
1 affected component
Emlog emlog<=1.0.7
Remediation
Patch Available
Event History
Jan 6, 2022
CVE Published
via MITRE·12:05 PM
Data Sourced
via MITRE·12:05 PM
Description
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-44584?
CVE-2021-44584 is a cross-site scripting (XSS) vulnerability in emlog version <= pro-1.0.7 that allows remote attackers to inject arbitrary web script or HTML via the s parameter.
2
How severe is CVE-2021-44584?
CVE-2021-44584 has a severity level of medium with a CVSS score of 6.1.
3
How can I exploit CVE-2021-44584?
To exploit CVE-2021-44584, remote attackers can inject arbitrary web script or HTML via the s parameter in index.php.
4
Is there a fix for CVE-2021-44584?
Yes, the vulnerability has been fixed in emlog version pro-1.0.8. Upgrade to this version to mitigate the risk.
5
What is the CWE ID for CVE-2021-44584?
The CWE ID for CVE-2021-44584 is CWE-79 (Cross-site Scripting).