CVE-2021-28975: XSS
WP Mailster 1.6.18.0 allows XSS when a victim opens a mail server's details in the mstservers page, for a crafted serverhost, servername, or connectionparameter parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28975?
The severity of CVE-2021-28975 is classified as medium, as it allows for Cross-Site Scripting (XSS) vulnerabilities.
How do I fix CVE-2021-28975?
To fix CVE-2021-28975, upgrade WP Mailster to version 1.6.19 or later where the vulnerability has been resolved.
What are the potential impacts of CVE-2021-28975?
The potential impacts of CVE-2021-28975 include unauthorized actions and exposure of sensitive user data through XSS.
Who is affected by CVE-2021-28975?
CVE-2021-28975 affects users of WP Mailster version 1.6.18 when they open the mail server's details page.
How can I determine if my website is vulnerable to CVE-2021-28975?
You can determine if your website is vulnerable to CVE-2021-28975 by checking if you are using WP Mailster version 1.6.18 and testing for XSS in the mst_servers page.