.. / CVE-2021-43810

Exploit for Admidio - Cross-Site Scripting (CVE-2021-43810)

Description:

A cross-site scripting vulnerability is present in Admidio prior to version 4.0.12. The reflected cross-site scripting vulnerability occurs because redirect.php does not properly validate the value of the url parameter. Through this vulnerability, an attacker is capable to execute malicious scripts.

Nuclei Template

View the template here CVE-2021-43810.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-43810.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2021-43810
https://github.com/Admidio/admidio/releases/tag/v4.0.12
https://github.com/Admidio/admidio/security/advisories/GHSA-3qgf-qgc3-42hh
https://github.com/Admidio/admidio/commit/c043267d362f7813543cc2785119bf3e3e54fe21
https://github.com/Admidio/admidio/commit/fcb0609abc1d2f65bc1377866bd678e5d891404b