Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2021-25894
Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the /magnoliaPublic/travel/members/login.html mgnlUserId parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.004
EPSS Ranking
59.8%
CVSS Severity
CVSS v3 Score
6.1
CVSS v2 Score
4.3
References
https://git.magnolia-cms.com/projects/MODULES/repos/public-user-registration/commits/80c096c24d39ba2050b778e68ef838d79d4811dc
https://www.itas.vn/itas-security-team-found-multi-vulnerabilities-on-magnolia-cms-platform/
https://www.magnolia-cms.com/
https://git.magnolia-cms.com/projects/MODULES/repos/public-user-registration/commits/80c096c24d39ba2050b778e68ef838d79d4811dc
https://www.itas.vn/itas-security-team-found-multi-vulnerabilities-on-magnolia-cms-platform/
https://www.magnolia-cms.com/
Products affected by CVE-2021-25894
Magnolia-Cms
»
Magnolia Cms
»
Version:
6.1.3
cpe:2.3:a:magnolia-cms:magnolia_cms:6.1.3
Magnolia-Cms
»
Magnolia Cms
»
Version:
6.1.4
cpe:2.3:a:magnolia-cms:magnolia_cms:6.1.4
Magnolia-Cms
»
Magnolia Cms
»
Version:
6.1.5
cpe:2.3:a:magnolia-cms:magnolia_cms:6.1.5
Magnolia-Cms
»
Magnolia Cms
»
Version:
6.1.6
cpe:2.3:a:magnolia-cms:magnolia_cms:6.1.6
Magnolia-Cms
»
Magnolia Cms
»
Version:
6.2.3
cpe:2.3:a:magnolia-cms:magnolia_cms:6.2.3
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved