CVE-2021-24435
The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues
- Affected products
- Titan Framework
- Gambit Titan Framework
- ≤ 1.12.1
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 1.8% (77th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2021-09-06
CVE-2021-24435 at NVD
1 known exploit for CVE-2021-24435
Proof-of-concept code and exploit modules indexed by Sploitus