CVE-2021-28047: XSS
Cross-Site Scripting (XSS) in Administrative Reports in Devolutions Remote Desktop Manager before 2021.1 allows remote authenticated users to inject arbitrary web script or HTML via multiple input fields.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-28047?
CVE-2021-28047 is a vulnerability in Devolutions Remote Desktop Manager that allows remote authenticated users to inject arbitrary web script or HTML via multiple input fields.
How severe is CVE-2021-28047?
CVE-2021-28047 has a severity rating of 5.4, which is considered medium.
How can the CVE-2021-28047 vulnerability be exploited?
CVE-2021-28047 can be exploited by remote authenticated users who can inject arbitrary web script or HTML via multiple input fields.
Which version of Devolutions Remote Desktop Manager is affected by CVE-2021-28047?
Devolutions Remote Desktop Manager before version 2021.1.0 is affected by CVE-2021-28047.
Is there a fix for CVE-2021-28047?
To fix CVE-2021-28047, update Devolutions Remote Desktop Manager to version 2021.1.0 or later.