Medium severity6.1NVD Advisory· Published Mar 16, 2022· Updated Jun 17, 2026
CVE-2021-45822
CVE-2021-45822
Description
A cross-site scripting vulnerability is present in Xbtit 3.1. The stored XSS vulnerability occurs because /ajaxchat/sendChatData.php does not properly validate the value of the "n" (POST) parameter. Through this vulnerability, an attacker is capable to execute malicious JavaScript code.
Affected products
4- cpe:2.3:a:btiteam:xbtit:3.1:*:*:*:*:*:*:*
- Xbtit/Xbtitdescription
- Range: 3.1
Patches
Vulnerability mechanics
References
2- emaragkos.gr/infosec-adventures/xbtit-3-1-xss-stored-amp-reflected/nvdExploitThird Party Advisory
- github.com/btiteam/xbtit-3.1/issues/7nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.