CVE-2021-3904: Cross-site Scripting (XSS) - Stored in getgrav/grav
Published Oct 27, 2021
·Updated
grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected Software
1 affected component
getgrav Grav<1.7.24
Remediation
Event History
Oct 27, 2021
CVE Published
via MITRE·09:10 PM
Data Sourced
via MITRE·09:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-3904.
2
What is the severity of CVE-2021-3904?
The severity of CVE-2021-3904 is medium (5.4).
3
What software is affected by CVE-2021-3904?
The software affected by CVE-2021-3904 is Grav (version up to 1.7.24).
4
What is the CWE ID for CVE-2021-3904?
The CWE ID for CVE-2021-3904 is CWE-79.
5
How do I fix CVE-2021-3904?
To fix CVE-2021-3904, update the Grav software to version 1.7.25 or later.