Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2021-3030

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Cute Editor for ASP.NET 6.4 存在一个反射型跨站脚本(XSS)漏洞,原因是 页面对 GET 参数的验证不当。一个远程且未认证的攻击者可以构造一个 URL,当该 URL 在一个已登录到运行此易受攻击组件的网站的浏览器会话中被受害者打开时,会在那個网站的安全上下文中执行任意 JavaScript 代码。

AI Predicted 6.1 Difficulty: Easy
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-3030

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in colorpicker_more.aspx. A remote, unauthenticated attacker can craft a URL that, once opened by a victim in a browser session authenticated to a site running the vulnerable component, executes arbitrary JavaScript in the security context of that site.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2021-3030

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-3030

登录查看更多情报信息。

Proof of Concept for CVE-2021-3030 (1)

Same Patch Batch · n/a · 2026-09-17 · 6 CVEs total

CVE-2026-92880 6.3 MEDIUM vgmstream EA SCHl parser vadpcm_decoder.c vadpcm_read_coefs_be out-of-bounds write
CVE-2026-92881 4.3 MEDIUM vgmstream AWB parser awb.c init_vgmstream_awb_memory divide by zero
CVE-2026-92879 4.3 MEDIUM vgmstream mus_acm.c parse_mus resource consumption
CVE-2026-52483 MitraStar路由器固件1.11认证命令注入漏洞
CVE-2025-55787 MailData邮件归档系统v4.2 SQL注入漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2021-3030

No comments yet


Leave a comment