CVE-2021-30134

php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
VendorProductVersion
php_curl_class_projectphp_curl_class
𝑥
< 2.3.2
ht_slider_range_for_amazon_affiliates_projectht_slider_range_for_amazon_affiliates
𝑥
< 1.1.6
qiwiwoo-qiwi-payment-gateway
𝑥
≤ 0.0.9
teamleadeteamleader_crm_forms
𝑥
< 2.1.0
ptwoopluginsinvoicing_with_invoicexpress_for_woocommerce
𝑥
< 3.0.3
shopello_api_projectshopello_api
𝑥
≤ 2.9.0
𝑥
= Vulnerable software versions