CVE-2021-38607: XSS
Published Aug 16, 2021
·Updated
Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input.
Affected Software
1 affected component
Crocoblock JetEngine<2.6.1
Event History
Aug 16, 2021
CVE Published
via MITRE·12:15 PM
Data Sourced
via MITRE·12:15 PM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-38607?
The severity of CVE-2021-38607 is considered to be high due to its potential for exploitation via XSS.
2
How do I fix CVE-2021-38607?
To fix CVE-2021-38607, upgrade Crocoblock JetEngine to version 2.6.1 or later.
3
Who is affected by CVE-2021-38607?
CVE-2021-38607 affects all versions of Crocoblock JetEngine prior to 2.6.1.
4
What kind of attack does CVE-2021-38607 enable?
CVE-2021-38607 enables cross-site scripting (XSS) attacks by remote authenticated users.
5
Is user authentication required to exploit CVE-2021-38607?
Yes, exploitation of CVE-2021-38607 requires that the attacker be a remote authenticated user.