CVE-2021-44082

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
29/03/2022
Last modified:
06/04/2022

Description

textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by uploading a webshell. To do so they must first steal the CSRF token before submitting a file upload request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:textpattern:textpattern:4.8.7:*:*:*:*:*:*:*