CVE-2021-36572: XSS
Published Dec 15, 2022
·Updated
Cross Site Scripting (XSS) vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via the user name field of the login page.
Affected Software
1 affected component
Feehi Feehicms<=2.1.1
Event History
Dec 15, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-36572?
CVE-2021-36572 is a Cross Site Scripting (XSS) vulnerability in Feehi CMS version up to and including 2.1.1.
2
How does CVE-2021-36572 work?
CVE-2021-36572 allows attackers to run arbitrary code by exploiting the user name field of the login page in Feehi CMS.
3
What is the severity of CVE-2021-36572?
The severity of CVE-2021-36572 is medium with a CVSSv3 score of 6.1.
4
How can I fix CVE-2021-36572?
To fix CVE-2021-36572, update Feehi CMS to version 2.1.2 or higher.
5
Where can I find more information about CVE-2021-36572?
For more information about CVE-2021-36572, you can refer to the official GitHub issue at https://github.com/liufee/cms/issues/58.