S4E just found a high-severity finding from ssl robot vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-45380 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in AppCMS  affects v. 2.0.101.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-45380
6.1
CVSS

AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

AppCMS is a powerful and popular software used in the development of web applications. This software is specially designed for managing the content of websites and web applications with ease. It provides various features like user management, content management, and resource management, which makes it an ideal choice for developers who want to create robust and scalable web applications.

However, AppCMS 2.0.101 has been found to have a vulnerability that could put its users at risk. The vulnerability, identified as CVE-2021-45380, is an XSS injection vulnerability that has been detected in the \templates\m\inc_head.php file of the software. This vulnerability makes it possible for attackers to execute malicious code in the user's browser, which could lead to the compromise of sensitive user information.

When exploited, the vulnerability could potentially lead to significant consequences for the victim. Attackers could use the vulnerability to gain access to sensitive user data, such as login credentials or personal information. Additionally, they could potentially use the compromised user account to gain access to other resources within the network. This vulnerability could, therefore, result in significant financial loss, as well as reputational damage for the affected organization.

At s4e.io, we take the security of our users' digital assets very seriously. Thanks to our advanced security features, including proactive scanning and monitoring, our users can be confident that their web applications are protected from vulnerabilities like CVE-2021-45380. By using our platform, users can stay on top of the latest security threats and quickly take action to keep their digital assets secure. Contact us today and let us help protect your web applications from security threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautions that can be taken. Some of these include:

  • Updating AppCMS to the latest version, which includes a fix for the vulnerability.
  • Implementing web application firewalls to block malicious traffic.
  • Running regular vulnerability scans to identify and patch any new vulnerabilities.
  • Regularly training staff on security best practices to reduce the risk of human error.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.