CVE-2021-27888: XSS
Published Mar 2, 2021
·Updated
ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters.
Affected Software
4 affected components
Zend ZendTo<=6.05-4
Zend ZendTo=6.06-1-beta
Zend ZendTo=6.06-2-beta
Zend ZendTo=6.06-3-beta
Event History
Mar 2, 2021
CVE Published
via MITRE·12:04 AM
Data Sourced
via MITRE·12:04 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-27888.
2
What is the severity of CVE-2021-27888?
The severity of CVE-2021-27888 is medium.
3
What is the affected software version for CVE-2021-27888?
The affected software versions for CVE-2021-27888 are ZendTo 6.05-4 beta, ZendTo 6.06-1 beta, ZendTo 6.06-2 beta, and ZendTo 6.06-3 beta.
4
What is the vulnerability description of CVE-2021-27888?
CVE-2021-27888 is a vulnerability in ZendTo before 6.06-4 Beta that allows cross-site scripting (XSS) during the display of a drop-off when a filename has unexpected characters.
5
How can I fix CVE-2021-27888?
To fix CVE-2021-27888, it is recommended to upgrade to ZendTo version 6.06-4 Beta or later.