{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-15T07:53:51.365","vulnerabilities":[{"cve":{"id":"CVE-2021-37392","sourceIdentifier":"cve@mitre.org","published":"2021-07-26T18:15:08.517","lastModified":"2024-11-21T06:15:04.540","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In RPCMS v1.8 and below, the \"nickname\" variable is not properly sanitized before being displayed on page. When the API functions are enabled, the attacker can use API to update user nickname with XSS payload and achieve stored XSS. Users who view the articles published by the injected user will trigger the XSS."},{"lang":"es","value":"En RPCMS versiones v1.8 por debajo, la variable \"nickname\" no se sanea correctamente antes de ser mostrada en la página. Cuando las funciones de la API están habilitadas, el atacante puede usar la API para actualizar el apodo del usuario con el payload de tipo XSS y lograr el XSS almacenado. Unos usuarios que vean los artículos publicados por el usuario inyectado desencadenarán el ataque de tipo XSS"}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:rpcms:rpcms:*:*:*:*:*:*:*:*","versionEndIncluding":"1.8","matchCriteriaId":"5755310D-B470-4257-9169-DC1AC3180438"}]}]}],"references":[{"url":"https://gist.github.com/victomteng1997/bfa1e0e07dd22f7e0b13256eda79626f","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/ralap-z/RPCMS/","source":"cve@mitre.org","tags":["Product"]},{"url":"https://gist.github.com/victomteng1997/bfa1e0e07dd22f7e0b13256eda79626f","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/ralap-z/RPCMS/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product"]}]}}]}