Junglewise Threat Intelligence

CVE-2021-3030: CuteSoft Cute Editor reflected cross-site scripting in colorpicker_more.aspx

CVE-2021-3030 · Severity: medium · CVSS 6.1 · Published 2026-09-17

Executive brief

Cute Editor for ASP.NET is a server-side component used to provide rich text editing capabilities in web applications. Version 6.4 contains a reflected cross-site scripting (XSS) vulnerability in the colorpicker_more.aspx page that allows an attacker to inject malicious JavaScript. An authenticated user tricked into clicking a crafted link could have their session hijacked, credentials stolen, or be redirected to malicious content.

Technical details

The vulnerability is a reflected cross-site scripting (CWE-79) flaw caused by improper validation of the Theme GET parameter in the colorpicker_more.aspx file. The vulnerable component fails to sanitize user input before reflecting it into an HTML attribute context, allowing an attacker to inject arbitrary JavaScript. The attack is triggered remotely via a crafted URL (no authentication required to craft the URL, though the victim must be authenticated to the hosting site for cookie theft). An attacker can chain this with social engineering to deliver a phishing link that executes arbitrary JavaScript in the victim's browser within the security context of the hosting application. No patch is known to exist; the vendor (CuteSoft) has not responded to disclosure attempts since 2021.

Affected products

  • CuteSoft Cute Editor for ASP.NET 6.4

Timeline

  • 2021-01-06: disclosed: CVE-2021-3030 reserved by MITRE
  • 2021: other: Vendor (CuteSoft) contacted directly; no response received
  • 2022-01-27: other: Discoverer followed up with CVE Program requesting publication after vendor non-response
  • 2026-04-08: other: Discoverer's second follow-up: CVE record still not published
  • 2026-09-17: other: Public reference published on GitHub; CVE record remains unpublished by MITRE

References