CVE-2021-42940

A Cross Site Scripting (XSS) vulnerability exists in Projeqtor 9.3.1 via /projeqtor/tool/saveAttachment.php, which allows an attacker to upload a SVG file containing malicious JavaScript code.
Configurations

Configuration 1 (hide)

cpe:2.3:a:projeqtor:projeqtor:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:28

Type Values Removed Values Added
References () https://truedigitalsecurity.com/services/penetration-testing-services/advisory-summary-2.2022-cve-2021-42940 - Exploit, Third Party Advisory () https://truedigitalsecurity.com/services/penetration-testing-services/advisory-summary-2.2022-cve-2021-42940 - Exploit, Third Party Advisory
References () https://www.projeqtor.org/en/ - Product, Vendor Advisory () https://www.projeqtor.org/en/ - Product, Vendor Advisory

Information

Published : 2022-02-11 16:15

Updated : 2024-11-21 06:28


NVD link : CVE-2021-42940

Mitre link : CVE-2021-42940

CVE.ORG link : CVE-2021-42940


JSON object : View

Products Affected

projeqtor

  • projeqtor
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')