CVE-2021-43725 is a reflected Cross-Site Scripting (XSS) vulnerability found in Spotweb version 1.5.1 and earlier, specifically within the SpotPage_login.php component. An unauthenticated remote attacker can exploit this by injecting malicious web script or HTML through the data[performredirect] parameter. Rated as Medium severity (CVSS 6.1), it requires user interaction and could lead to limited impact on confidentiality and integrity. While no active exploitation or public exploit code (Metasploit, ExploitDB) has been observed, a Nuclei template exists for detection, and there is minimal community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.5.1CPE matchmatch criteria | cpe:2.3:a:spotweb_project:spotweb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.