CVE-2021-47808: Cotonti Siena 0.9.19 - 'maintitle' Stored Cross-Site Scripting
Cotonti Siena 0.9.19 contains a stored cross-site scripting vulnerability in the admin configuration panel's site title parameter. Attackers can inject malicious JavaScript code through the 'maintitle' parameter to execute scripts when administrators view the page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47808?
CVE-2021-47808 is classified as a high severity cross-site scripting vulnerability.
How do I fix CVE-2021-47808?
To fix CVE-2021-47808, update Cotonti Siena to the latest version that addresses this vulnerability.
What is the impact of CVE-2021-47808?
The impact of CVE-2021-47808 is that it allows attackers to inject malicious JavaScript, potentially compromising user data and site integrity.
In which software is CVE-2021-47808 found?
CVE-2021-47808 is found in Cotonti Siena version 0.9.19.
Who is affected by CVE-2021-47808?
Any admin user of Cotonti Siena 0.9.19 can be affected by CVE-2021-47808 due to the vulnerability in the site title parameter.