Description
Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in colorpicker_more.aspx. A remote, unauthenticated attacker can craft a URL that, once opened by a victim in a browser session authenticated to a site running the vulnerable component, executes arbitrary JavaScript in the security context of that site.
Published: 2026-09-17
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Script Execution via Cross‑Site Scripting
Action: Assess Impact
AI Analysis

Impact

Cute Editor for ASP.NET 6.4 contains a reflected cross‑site scripting vulnerability caused by insufficient validation of the Theme query string parameter in colorpicker_more.aspx. The flaw allows a remote attacker to construct a URL that, when visited by a victim who is logged into a site hosting the vulnerable component, results in the execution of arbitrary JavaScript within the victim’s browser. This code runs in the security context of that site, providing the attacker with the ability to steal session cookies, perform actions on behalf of the victim, or conduct further attacks.

Affected Systems

The vulnerability affects the Cute Editor for ASP.NET component version 6.4, specifically the colorpicker_more.aspx page that accepts a Theme parameter. It only impacts installations that include this component and are reachable via a web interface.

Risk and Exploitability

The CVSS base score is 6.1, indicating a medium level of severity, while the EPSS score is below 1%, suggesting that the likelihood of exploitation in the wild is currently low. The vulnerability is not listed in the CISA KEV catalog. The attack can be launched remotely without authentication; however, the victim must be already logged into the affected web application for the reflected script to execute. The exploit requires a malicious link that uses a crafted Theme parameter, which will be injected and reflected back into the page’s HTML, causing JavaScript execution.

Generated by OpenCVE AI on September 20, 2026 at 04:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check whether the Cute Editor for ASP.NET 6.4 component is present on your web servers and locate all instances of colorpicker_more.aspx.
  • Apply any official update or patch from the vendor; if no update is available, sanitize the Theme query string so that only valid characters (for example, a predefined list of theme names) are accepted before echoing it back to the browser.
  • Deploy a strict Content Security Policy that disallows inline scripts and permits scripts only from trusted origins on pages that host Cute Editor.
  • Enable XSS filtering and request headers such as X‑Content‑Type‑Options: nosniff to reduce the impact if the vulnerability remains unresolved.

Generated by OpenCVE AI on September 20, 2026 at 04:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Cute Editor for ASP.NET 6.4 Vulnerable to Reflected Cross‑Site Scripting via Theme Parameter

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in colorpicker_more.aspx. A remote, unauthenticated attacker can craft a URL that, once opened by a victim in a browser session authenticated to a site running the vulnerable component, executes arbitrary JavaScript in the security context of that site.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-18T13:36:03.597Z

Reserved: 2021-01-06T00:00:00.000Z

Link: CVE-2021-3030

cve-icon Vulnrichment

Updated: 2026-09-18T13:35:15.893Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T21:17:10.213

Modified: 2026-09-22T20:00:03.713

Link: CVE-2021-3030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:45:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')