Low severity3.5NVD Advisory· Published Dec 21, 2022· Updated Jun 17, 2026
CVE-2021-4266
CVE-2021-4266
Description
A vulnerability classified as problematic has been found in Webdetails cpf up to 9.5.0.0-80. Affected is an unknown function of the file core/src/main/java/pt/webdetails/cpf/packager/DependenciesPackage.java. The manipulation of the argument baseUrl leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 9.5.0.0-81 is able to address this issue. The name of the patch is 3bff900d228e8cae3af256b447c5d15bdb03c174. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216468.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:hitachi:community_plugin_framework:*:*:*:*:*:*:*:*Range: <9.5.0.0-81
<=9.5.0.0-80+ 1 more
- (no CPE)range: <=9.5.0.0-80
- (no CPE)range: 9.5.0.0-80
Patches
Vulnerability mechanics
References
4- github.com/webdetails/cpf/commit/3bff900d228e8cae3af256b447c5d15bdb03c174nvdPatchThird Party Advisory
- github.com/webdetails/cpf/releases/tag/9.5.0.0-81nvdRelease NotesThird Party Advisory
- vuldb.comnvdThird Party AdvisoryVDB Entry
- github.com/siwapp/siwapp-ror/pull/365nvdNot Applicable
News mentions
0No linked articles in our index yet.