CVE-2021-43810 | Cross-site Scripting (XSS) when redirect an url
Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vulnerability is present in Admidio prior to version 4.0.12. The Reflected XSS vulnerability occurs because redirect.php does not properly validate the value of the url parameter. Through this vulnerability, an attacker is capable to execute malicious scripts. This issue is patched in version 4.0.12.
Conclusion & alert: CVE-2021-43810 is rated High Risk (67.8/100): CVSS High severity, with high exploitation likelihood (EPSS 70.93%, 99th percentile).Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term.Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Exploit prediction scoring system (EPSS) score for CVE-2021-43810
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).