CVE-2021-37502: XSS
Published Feb 3, 2023
·Updated
Cross Site Scripting (XSS) vulnerability in automad 1.7.5 allows remote attackers to run arbitrary code via the user name field when adding a user.
Affected Software
2 affected componentsFixes available
composer/automad/automad<1.8.0
1.8.0
Automad Automad=1.7.5
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
via GitHub·06:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-37502?
CVE-2021-37502 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2021-37502?
To fix CVE-2021-37502, upgrade Automad to version 1.8.0 or later.
3
Which version of Automad is affected by CVE-2021-37502?
CVE-2021-37502 affects Automad version 1.7.5.
4
Can CVE-2021-37502 be exploited remotely?
Yes, CVE-2021-37502 can be exploited remotely by attackers through the username field.
5
What type of vulnerability is CVE-2021-37502?
CVE-2021-37502 is a cross-site scripting (XSS) vulnerability.