S4E just found a medium snmp system information scanner
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-41951 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in ResourceSpace affects v. before 9.6.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-41951
6.1
CVSS

ResourceSpace before 9.6 rev 18290 is affected by a reflected Cross-Site Scripting vulnerability in plugins/wordpress_sso/pages/index.php via the wordpress_user parameter. If an attacker is able to persuade a victim to visit a crafted URL, malicious JavaScript content may be executed within the context of the victim's browser.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

ResourceSpace is a free and open-source digital asset management system that enables organizations to manage, store, and share digital content such as images, videos, and documents. It offers a wide range of functionalities for digital asset management, including file conversions, metadata management, version control, and access control.

However, ResourceSpace is not immune to vulnerabilities, and one of the most recent ones detected is CVE-2021-41951. This vulnerability is a reflected Cross-Site Scripting (XSS) that affects versions before 9.6 rev 18290. It is located in the WordPress Single Sign-On (SSO) plugin's index.php page via the wordpress_user parameter. If an attacker can convince a victim to visit a specially crafted URL, malicious JavaScript code can be executed within the victim's browser. This can lead to sensitive data exposure, data theft, and website defacement.

The exploitation of the CVE-2021-41951 vulnerability can lead to various negative consequences. Attackers can leverage the vulnerability to retrieve sensitive data such as login credentials, personal information, and financial data. This data can then be used for fraudulent activities such as identity theft and account hijacking. Moreover, attackers can also use this vulnerability to inject and execute malicious code, leading to further compromise of the system.

Thanks to the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. The platform offers a comprehensive vulnerability scanning tool that can scan websites and web applications for vulnerabilities, including XSS and other common vulnerabilities. This can help businesses and organizations stay ahead of threats and protect their digital assets effectively.

 

REFERENCES

Solution Advice

To protect against this vulnerability, ResourceSpace users can take the following precautions:

  • Update to the latest version of ResourceSpace to ensure the vulnerability is patched.
  • Disable the WordPress SSO plugin until a patch is available.
  • Educate employees and staff about social engineering tactics and how to identify and avoid suspicious links.
  • Implement web application firewalls and other security measures to detect and block malicious traffic.
  • Regularly monitor and audit the system for signs of compromise or suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-41951 scanner - Cross-Site Scripting (XSS) vulnerability in ResourceSpace S4E