CVE-2021-41791: XSS
An issue was discovered in Hyland org.alfresco:share through 7.0.0.2 and org.alfresco:community-share through 7.0. An evasion of the XSS filter for HTML input validation in the Alfresco Share User Interface leads to stored XSS that could be exploited by an attacker (given that he has privileges on the content collaboration features).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-41791.
What is the severity level of CVE-2021-41791?
The severity level of CVE-2021-41791 is medium, with a CVSS score of 5.4.
What is the affected software for CVE-2021-41791?
The affected software for CVE-2021-41791 includes Alfresco Share versions 5.0.0.0 to 5.2.7.11, 6.0.1.0 to 6.0.1.2, 6.0.2.0 to 6.2.2.4, and 6.1.1.0 to 6.1.1.2, as well as Alfresco Community Share version 7.0.
What is the description of CVE-2021-41791?
CVE-2021-41791 is an issue in Hyland org.alfresco:share through 7.0.0.2 and org.alfresco:community-share through 7.0 that allows for an evasion of the XSS filter, leading to a stored XSS vulnerability that can be exploited by an attacker with privileges.
How can CVE-2021-41791 be fixed?
To fix CVE-2021-41791, it is recommended to update to a patched version of Alfresco Share or Alfresco Community Share.