S4E just found a high-severity finding from cve-2001-1473 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-43810 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Admidio  (open source project) affects v. <4.0.12.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
5.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-43810
6.1
CVSShigh
Exploitable remotely over the internet · no authentication required · user interaction needed.

Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vulnerability is present in Admidio prior to version 4.0.12. The Reflected XSS vulnerability occurs because redirect.php does not properly validate the value of the url parameter. Through this vulnerability, an attacker is capable to execute malicious scripts. This issue is patched in version 4.0.12.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
admidioby Admidio
< 4.0.12
Updated Aug 21, 2026View on NVD →
Detail

Admidio is a free open-source user management system designed for websites of organizations and groups. It aims to ease the administrative burden of managing website users by providing a reliable and user-friendly platform for managing members, events, and communication.

Recently, a Cross-Site Scripting (XSS) vulnerability CVE-2021-43810 was detected in the Admidio system prior to version 4.0.12. This vulnerability occurs due to inadequate validation of the value of the url parameter in redirect.php. By exploiting this vulnerability, attackers can execute crafted scripts and steal sensitive information, such as login credentials and personal user information.

When the above vulnerability is exploited, it can lead to the infiltration of malicious code onto devices of the users of the platform. This can potentially lead to the exposure of critical information, such as user login credentials and personal information. In addition, it may result in the compromise of the server and the whole system, which would lead to a complete loss of all user data and unauthorized access to sensitive systems.

With the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. The platform provides comprehensive scans of websites, highlighting all vulnerabilities, including XSS, SQL Injection, and others. It also provides expert advice on eliminating discovered vulnerabilities and securing their website to ensure that the user's information is safe and protected.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users must update their systems to version 4.0.12, which includes a patch for the vulnerability. Additionally, users can follow these precautions:

  • Ensure all software installed on servers is up-to-date.
  • Enable two-factor authentication to add an extra layer of security for user logins.
  • Utilize a Web Application Firewall (WAF) that can detect and block malicious traffic attempting to exploit vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.