CVE-2021-27902: XSS
Published Jun 30, 2021
·Updated
An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.
Affected Software
2 affected componentsFixes available
composer/craftcms/cms<3.6.0
3.6.0
Craft CMS<3.6.0
Remediation
Event History
Jun 30, 2021
CVE Published
via MITRE·11:56 AM
Data Sourced
via MITRE·11:56 AM
Description
Jul 2, 2021
Advisory Published
06:36 PM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-27902.
2
What is the severity of CVE-2021-27902?
The severity of CVE-2021-27902 is medium with a CVSS score of 6.1.
3
What is the affected software version of CVE-2021-27902?
The affected software version of CVE-2021-27902 is Craft CMS before version 3.6.0.
4
What is the vulnerability type of CVE-2021-27902?
CVE-2021-27902 is a cross-site scripting (XSS) vulnerability.
5
How do I fix CVE-2021-27902?
To fix CVE-2021-27902, upgrade to Craft CMS version 3.6.0 or later.