CVE-2021-27558: XSS
A cross site scripting (XSS) issue in EasyCorp ZenTao 12.5.3 allows remote attackers to execute arbitrary web script via various areas such as data-link-creator.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-27558?
CVE-2021-27558 is a cross site scripting (XSS) issue in EasyCorp ZenTao 12.5.3 that allows remote attackers to execute arbitrary web script via various areas such as data-link-creator.
How does CVE-2021-27558 impact EasyCorp ZenTao?
CVE-2021-27558 allows remote attackers to execute arbitrary web script, posing a security risk to EasyCorp ZenTao 12.5.3.
What is the severity of CVE-2021-27558?
CVE-2021-27558 has a severity rating of medium with a CVSS score of 6.1.
How can I fix CVE-2021-27558?
To fix CVE-2021-27558, it is recommended to update EasyCorp ZenTao to a version that includes the necessary security patches.
Is there any additional information available about CVE-2021-27558?
Yes, you can find more information about CVE-2021-27558 at https://privasec.com/blog/zentao-cms-a-monkeys-journey-to-priv-esc-remote-code-execution/