CVE-2021-35265: XSS
Published Aug 3, 2021
·Updated
A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/ allows remote attackers to inject arbitrary web script to a page.
Affected Software
1 affected component
Maxsite MaxSite CMS<106
Remediation
Event History
Aug 3, 2021
CVE Published
via MITRE·11:55 AM
Data Sourced
via MITRE·11:55 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-35265?
CVE-2021-35265 is classified as a critical vulnerability due to its potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2021-35265?
To fix CVE-2021-35265, update MaxSite CMS to version 106 or later, where the vulnerability has been addressed.
3
Who is affected by CVE-2021-35265?
Any users running MaxSite CMS versions prior to 106 are affected by CVE-2021-35265.
4
What type of vulnerability is CVE-2021-35265?
CVE-2021-35265 is a reflected cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2021-35265?
Attackers can inject arbitrary web scripts into pages, potentially leading to unauthorized actions or data theft.