CVE-2021-39491: XSS
Published Mar 24, 2022
·Updated
A Cross Site Scripting (XSS) vulnerability exists in Yogesh Ojha reNgine v1.0 via the Scan Engine name file in the Scan Engine deletion confirmation modal box . .
Affected Software
1 affected component
Rengine Project Rengine<1.0.1
Remediation
Patch Available
Event History
Mar 24, 2022
CVE Published
via MITRE·02:24 PM
Data Sourced
via MITRE·02:24 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-39491?
CVE-2021-39491 is classified as a medium severity Cross Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2021-39491?
To fix CVE-2021-39491, update to version 1.0.1 or later of reNgine software.
3
What impact does CVE-2021-39491 have on users?
CVE-2021-39491 allows attackers to execute arbitrary scripts in the context of the user’s browser.
4
In which versions of reNgine is CVE-2021-39491 present?
CVE-2021-39491 is present in all versions of reNgine up to version 1.0.1.
5
How can I determine if I am affected by CVE-2021-39491?
You are affected by CVE-2021-39491 if you are using reNgine version lower than 1.0.1.