{"id":"CVE-2021-32106","aliases":["GHSA-jf9v-q8vh-3fmc"],"url":"https://o3.security/vulnerability/CVE-2021-32106","summary":"Cross-site scripting in ICEcoder","details":"In ICEcoder 8.0 allows, a reflected XSS vulnerability was identified in the multipe-results.php page due to insufficient sanitization of the _GET['replace'] variable. As a result, arbitrary Javascript code can get executed.","published":"2021-06-08T13:15:07.640Z","modified":"2026-07-09T01:31:29.790479Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"icecoder/icecoder","fixedVersion":"8.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://prophaze.com/cve/icecoder-8-0-multipe-results-php-replace-cross-site-scripting/"},{"type":"PACKAGE","url":"https://github.com/icecoder/ICEcoder"},{"type":"EVIDENCE","url":"https://groups.google.com/g/icecoder/c/xcAc8_1UPxQ"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T01:31:29.790479Z"}}