Vulnerability Details CVE-2021-44116
Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column to upload the title and content containing malicious code to achieve the purpose of obtaining the administrator cookie, thereby achieving other malicious operations.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 47.2%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2021-44116
-
cpe:2.3:a:anchorcms:anchor_cms:0.11
-
cpe:2.3:a:anchorcms:anchor_cms:0.12
-
cpe:2.3:a:anchorcms:anchor_cms:0.12.1
-
cpe:2.3:a:anchorcms:anchor_cms:0.12.3
-
cpe:2.3:a:anchorcms:anchor_cms:0.12.6
-
cpe:2.3:a:anchorcms:anchor_cms:0.12.7
-
cpe:2.3:a:anchorcms:anchor_cms:0.4
-
cpe:2.3:a:anchorcms:anchor_cms:0.5
-
cpe:2.3:a:anchorcms:anchor_cms:0.6
-
cpe:2.3:a:anchorcms:anchor_cms:0.7
-
cpe:2.3:a:anchorcms:anchor_cms:0.7.2
-
cpe:2.3:a:anchorcms:anchor_cms:0.8
-
cpe:2.3:a:anchorcms:anchor_cms:0.8.1
-
cpe:2.3:a:anchorcms:anchor_cms:0.8.2
-
cpe:2.3:a:anchorcms:anchor_cms:0.8.3
-
cpe:2.3:a:anchorcms:anchor_cms:0.9
-
cpe:2.3:a:anchorcms:anchor_cms:0.9.1
-
cpe:2.3:a:anchorcms:anchor_cms:0.9.2
-
cpe:2.3:a:anchorcms:anchor_cms:0.9.3
-
cpe:2.3:a:anchorcms:anchor_cms:0.9.3.1