CVE-2021-28977: XSS
Published Jun 23, 2021
·Updated
Cross Site Scripting vulnerability in GetSimpleCMS 3.3.16 in admin/upload.php by adding comments or jpg and other file header information to the content of xla, pages, and gzip files,
Affected Software
1 affected component
Get-simple Getsimplecms<=3.3.15
Event History
Jun 23, 2021
CVE Published
via MITRE·12:44 PM
Data Sourced
via MITRE·12:44 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-28977?
The severity of CVE-2021-28977 is medium with a CVSS score of 4.8.
2
How does CVE-2021-28977 affect GetSimpleCMS?
CVE-2021-28977 affects GetSimpleCMS versions up to and including 3.3.15.
3
How can an attacker exploit CVE-2021-28977?
An attacker can exploit CVE-2021-28977 by adding malicious comments or injecting file header information into xla, pages, and gzip files in GetSimpleCMS's admin/upload.php.
4
Is there a fix available for CVE-2021-28977?
Yes, upgrading to GetSimpleCMS 3.3.16 or later will fix CVE-2021-28977.
5
Where can I find more information about CVE-2021-28977?
More information about CVE-2021-28977 can be found at this link: [reference](https://github.com/GetSimpleCMS/GetSimpleCMS/issues/1336).