First published: Fri Nov 19 2021(Updated: )
grav-plugin-admin is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Getgrav Grav-plugin-admin | <1.10.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3920 is a vulnerability in grav-plugin-admin that allows for 'Cross-site Scripting' attacks.
CVE-2021-3920 has a severity rating of 5.4 (medium).
CVE-2021-3920 allows malicious actors to execute 'Cross-site Scripting' attacks on grav-plugin-admin.
Yes, a fix for CVE-2021-3920 is available in the latest version of grav-plugin-admin.
You can find more information about CVE-2021-3920 on the GitHub commit and the Huntr.dev bounty page.