First published: Thu Mar 17 2022(Updated: )
Slims9 Bulian 9.4.2 is affected by Cross Site Scripting (XSS) in /admin/modules/system/custom_field.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Library Management System | =9.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45792 is a vulnerability in Slims9 Bulian 9.4.2 that allows for Cross Site Scripting (XSS) attacks in /admin/modules/system/custom_field.php.
CVE-2021-45792 can be exploited by an attacker to perform XSS attacks, which can lead to the execution of malicious scripts and the theft of sensitive information.
CVE-2021-45792 has a severity rating of medium with a CVSS score of 4.8.
Currently, there is no official fix or patch available for CVE-2021-45792 in Slims9 Bulian 9.4.2, but implementing proper input validation and output encoding can help mitigate the risk.
You can find more information about CVE-2021-45792 in the GitHub issue: https://github.com/slims/slims9_bulian/issues/122.