CVE-2021-28088: XSS
Published Mar 11, 2021
·Updated
Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary web script or HTML parameters through the "Display Name" field.
Affected Software
1 affected component
ImpressCMS ImpressCMS=1.4.2
Event History
Mar 11, 2021
CVE Published
via MITRE·04:23 PM
Data Sourced
via MITRE·04:23 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-28088?
The severity of CVE-2021-28088 is classified as medium due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2021-28088?
To fix CVE-2021-28088, update your ImpressCMS to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2021-28088?
Users of ImpressCMS version 1.4.2 are affected by CVE-2021-28088 and should take remediation measures.
4
What kind of attack does CVE-2021-28088 enable?
CVE-2021-28088 enables remote attackers to execute arbitrary web script or HTML via the 'Display Name' field.
5
Is there a known exploit for CVE-2021-28088?
Yes, there are reports confirming the exploitation of CVE-2021-28088 in the wild.