CVE-2021-3785: Cross-site Scripting (XSS) - Stored in yourls/yourls
Published Sep 15, 2021
·Updated
yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected Software
1 affected component
Yourls Yourls<1.8.2
Remediation
Event History
Sep 15, 2021
CVE Published
via MITRE·12:05 PM
Data Sourced
via MITRE·12:05 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this security vulnerability?
The vulnerability ID for this security vulnerability is CVE-2021-3785.
2
What is the severity of CVE-2021-3785?
The severity of CVE-2021-3785 is high with a severity score of 5.4.
3
What is the affected software in CVE-2021-3785?
The affected software in CVE-2021-3785 is Yourls version up to and exclusive 1.8.2.
4
What is the CWE ID for CVE-2021-3785?
The CWE ID for CVE-2021-3785 is CWE-79.
5
How do I fix CVE-2021-3785?
To fix CVE-2021-3785, it is recommended to update Yourls to a version higher than or equal to 1.8.2.