Vulnerability Details CVE-2021-44116
Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column to upload the title and content containing malicious code to achieve the purpose of obtaining the administrator cookie, thereby achieving other malicious operations.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 49.9%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2021-44116
-
cpe:2.3:a:anchorcms:anchor_cms:0.11
-
cpe:2.3:a:anchorcms:anchor_cms:0.12
-
cpe:2.3:a:anchorcms:anchor_cms:0.12.1
-
cpe:2.3:a:anchorcms:anchor_cms:0.12.3
-
cpe:2.3:a:anchorcms:anchor_cms:0.12.6
-
cpe:2.3:a:anchorcms:anchor_cms:0.12.7
-
cpe:2.3:a:anchorcms:anchor_cms:0.4
-
cpe:2.3:a:anchorcms:anchor_cms:0.5
-
cpe:2.3:a:anchorcms:anchor_cms:0.6
-
cpe:2.3:a:anchorcms:anchor_cms:0.7
-
cpe:2.3:a:anchorcms:anchor_cms:0.7.2
-
cpe:2.3:a:anchorcms:anchor_cms:0.8
-
cpe:2.3:a:anchorcms:anchor_cms:0.8.1
-
cpe:2.3:a:anchorcms:anchor_cms:0.8.2
-
cpe:2.3:a:anchorcms:anchor_cms:0.8.3
-
cpe:2.3:a:anchorcms:anchor_cms:0.9
-
cpe:2.3:a:anchorcms:anchor_cms:0.9.1
-
cpe:2.3:a:anchorcms:anchor_cms:0.9.2
-
cpe:2.3:a:anchorcms:anchor_cms:0.9.3
-
cpe:2.3:a:anchorcms:anchor_cms:0.9.3.1