Cross Site Scripting (XSS) vulnerability exists in Catfish <=6.3.0 via a Google search in url:/catfishcms/index.php/admin/Index/addmenu.htmland then the .html file on the website that uses this editor (the file suffix is allowed).
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T04:32:13.602Z

Reserved: 2021-12-13T00:00:00

Link: CVE-2021-45018

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-15T23:15:08.897

Modified: 2024-11-21T06:31:49.000

Link: CVE-2021-45018

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.