« Volver al listado

CVE-2021-29399

Estado: ModificadaMedia (6.1)—

XMB is vulnerable to cross-site scripting (XSS) due to inadequate filtering of BBCode input. This bug affects all versions of XMB. All XMB installations must be updated to versions 1.9.12.03 or 1.9.11.16.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-29399",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-04-19T12:15:18.553",
  "references": [
    {
      "url": "https://docs.xmbforum2.com/index.php?title=Security_Issue_History",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://forums.xmbforum2.com/viewthread.php?tid=777105",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.xmbforum2.com/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://docs.xmbforum2.com/index.php?title=Security_Issue_History",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://forums.xmbforum2.com/viewthread.php?tid=777105",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.xmbforum2.com/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "XMB is vulnerable to cross-site scripting (XSS) due to inadequate filtering of BBCode input. This bug affects all versions of XMB. All XMB installations must be updated to versions 1.9.12.03 or 1.9.11.16."
    },
    {
      "lang": "es",
      "value": "XMB es vulnerable a un ataque de tipo cross-site scripting (XSS) debido a un filtrado inadecuado de la entrada de BBCode. Este bug afecta a todas las versiones de XMB. Todas las instalaciones de XMB deben ser actualizadas a las versiones 1.9.12.03 o 1.9.11.16"
    }
  ],
  "lastModified": "2026-06-17T03:47:35.487",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:xmbforum2:xmb:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5B563F5-9FB3-41A6-991F-606162F49915",
              "versionEndExcluding": "1.9.11.16",
              "versionStartIncluding": "1.9.1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:php:php:5.0.0:-:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8004A58C-C291-4489-A852-D3E07D82BD9C"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:xmbforum2:xmb:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "74A29A96-1A14-45F5-96C7-CB9764F40089",
              "versionEndExcluding": "1.9.11.16",
              "versionStartIncluding": "1.9.11"
            },
            {
              "criteria": "cpe:2.3:a:xmbforum2:xmb:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76480995-DE4A-4404-BDCD-2627230077E2",
              "versionEndExcluding": "1.9.12.03",
              "versionStartIncluding": "1.9.12"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:php:php:7.0.0:-:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E5C4C35D-F8FE-429F-8F6E-9178EAB21772"
            },
            {
              "criteria": "cpe:2.3:a:php:php:8.0.0:-:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "6CC80B03-CD93-4B0F-91DC-21BCF9BA42C5"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}