CVE-2021-33347: XSS
Published Jun 18, 2021
·Updated
An issue was discovered in JPress v3.3.0 and below. There are XSS vulnerabilities in the template module and tag management module. If you log in to the background by means of weak password, the storage XSS vulnerability can occur.
Affected Software
1 affected component
jpress Jpress<=3.3.0
Event History
Jun 18, 2021
CVE Published
via MITRE·10:43 AM
Data Sourced
via MITRE·10:43 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-33347?
CVE-2021-33347 is classified as a medium severity vulnerability due to the potential for exploitation via XSS attacks.
2
How do I fix CVE-2021-33347?
To fix CVE-2021-33347, upgrade to JPress version 3.4.0 or later to mitigate the XSS vulnerabilities.
3
What are the implications of CVE-2021-33347?
The implications of CVE-2021-33347 include the risk of stored XSS attacks if weak passwords are used for background login.
4
Which versions of JPress are affected by CVE-2021-33347?
JPress versions 3.3.0 and below are affected by CVE-2021-33347.
5
What types of vulnerabilities are found in CVE-2021-33347?
CVE-2021-33347 contains XSS vulnerabilities in the template module and tag management module.