First published: Fri Jun 18 2021(Updated: )
An issue was discovered in JPress v3.3.0 and below. There are XSS vulnerabilities in the template module and tag management module. If you log in to the background by means of weak password, the storage XSS vulnerability can occur.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
openMairie Openpresse | <=3.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33347 is classified as a medium severity vulnerability due to the potential for exploitation via XSS attacks.
To fix CVE-2021-33347, upgrade to JPress version 3.4.0 or later to mitigate the XSS vulnerabilities.
The implications of CVE-2021-33347 include the risk of stored XSS attacks if weak passwords are used for background login.
JPress versions 3.3.0 and below are affected by CVE-2021-33347.
CVE-2021-33347 contains XSS vulnerabilities in the template module and tag management module.