Show plain JSON{"id": "CVE-2021-39413", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "CHANGED", "version": "3.1", "baseScore": 6.1, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "integrityImpact": "LOW", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 2.7, "exploitabilityScore": 2.8}]}, "published": "2021-11-05T16:15:07.653", "references": [{"url": "https://sisl.lab.uic.edu/projects/chess/seo-panel/", "tags": ["Exploit", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://sisl.lab.uic.edu/projects/chess/seo-panel/", "tags": ["Exploit", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-79"}]}], "descriptions": [{"lang": "en", "value": "Multiple Cross Site Scripting (XSS) vulnerabilities exits in SEO Panel v4.8.0 via the (1) to_time parameter in (a) backlinks.php, (b) analytics.php, (c) log.php, (d) overview.php, (e) pagespeed.php, (f) rank.php, (g) review.php, (h) saturationchecker.php, (i) social_media.php, and (j) reports.php; the (2) from_time parameter in (a) backlinks.php, (b) analytics.php, (c) log.php, (d) overview.php, (e) pagespeed.php, (f) rank.php, (g) review.php, (h) saturationchecker.php, (i) social_media.php, (j) webmaster-tools.php, and (k) reports.php; the (3) order_col parameter in (a) analytics.php, (b) review.php, (c) social_media.php, and (d) webmaster-tools.php; and the (4) pageno parameter in (a) alerts.php, (b) log.php, (c) keywords.php, (d) proxy.php, (e) searchengine.php, and (f) siteauditor.php."}, {"lang": "es", "value": "Se presentan m\u00faltiples vulnerabilidades de tipo Cross Site Scripting (XSS) en SEO Panel versi\u00f3n v4.8.0 por medio del par\u00e1metro (1) to_time en los archivos: (a) backlinks.php, (b) analytics.php, (c) log.php, (d) overview.php, (e) pagespeed. php, (f) rank.php, (g) review.php, (h) saturationchecker.php, (i) social_media.php, y (j) reports.php; el par\u00e1metro (2) from_time en los archivos: (a) backlinks.php, (b) analytics.php, (c) log.php, (d) overview. php, (e) pagespeed.php, (f) rank.php, (g) review.php, (h) saturationchecker.php, (i) social_media.php, (j) webmaster-tools.php, y (k) reports.php; el par\u00e1metro (3) order_col en los archivos: (a) analytics.php, (b) review. php, (c) social_media.php, y (d) webmaster-tools.php; y el par\u00e1metro (4) pageno en los archivos: (a) alerts.php, (b) log.php, (c) keywords.php, (d) proxy.php, (e) searchengine.php, y (f) siteauditor.php"}], "lastModified": "2024-11-21T06:19:29.877", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:seopanel:seo_panel:4.8.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA338EF9-AC8B-411D-8BE3-9F9A2E68F8E0"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}