Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2021-23260

Description

Authenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and other users of the same site.

POC

Reference

No PoCs from references.

Github

- https://github.com/ARPSyndicate/cvemon

- https://github.com/Hax0rG1rl/my_cve_and_bounty_poc

- https://github.com/happyhacking-k/happyhacking-k

- https://github.com/happyhacking-k/my_cve_and_bounty_poc