CVE-2021-43686

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
02/12/2021
Last modified:
03/12/2021

Description

nZEDb v0.4.20 is affected by a Cross Site Scripting (XSS) vulnerability in www/pages/api.php. The exit function will terminate the script and print the message which has the input $_GET['t'].

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nzedb_project:nzedb:0.4.20:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools