CVE-2021-36712: XSS
Published Feb 3, 2023
·Updated
Cross Site Scripting (XSS) vulnerability in yzmcms 6.1 allows attackers to steal user cookies via image clipping function.
Affected Software
1 affected component
YzmCMS YzmCMS=6.1
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-36712?
CVE-2021-36712 is considered a medium severity vulnerability due to its potential for XSS attacks.
2
How do I fix CVE-2021-36712?
To fix CVE-2021-36712, update your Yzmcms software to a version that addresses this vulnerability.
3
What kind of vulnerability is CVE-2021-36712?
CVE-2021-36712 is a Cross Site Scripting (XSS) vulnerability.
4
What can attackers do with CVE-2021-36712?
Attackers can exploit CVE-2021-36712 to steal user cookies through the image clipping function.
5
Which versions of Yzmcms are affected by CVE-2021-36712?
CVE-2021-36712 specifically affects Yzmcms version 6.1.