First published: Mon Aug 16 2021(Updated: )
Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JetEngine | <2.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-38607 is considered to be high due to its potential for exploitation via XSS.
To fix CVE-2021-38607, upgrade Crocoblock JetEngine to version 2.6.1 or later.
CVE-2021-38607 affects all versions of Crocoblock JetEngine prior to 2.6.1.
CVE-2021-38607 enables cross-site scripting (XSS) attacks by remote authenticated users.
Yes, exploitation of CVE-2021-38607 requires that the attacker be a remote authenticated user.