First published: Wed Jan 19 2022(Updated: )
A reflected cross-site scripting (XSS) vulnerability in \lib\packages\themes\themes.php of Navigate CMS v2.9.4 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Naviwebs Navigate CMS | =2.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44299 is a reflected cross-site scripting (XSS) vulnerability in Navigate CMS v2.9.4.
CVE-2021-44299 allows authenticated attackers to execute arbitrary web scripts or HTML through a crafted payload.
CVE-2021-44299 has a severity rating of medium (5.4) according to the Common Vulnerability Scoring System (CVSS).
To fix CVE-2021-44299, upgrade to a version of Navigate CMS that includes the necessary security patches.
More information about CVE-2021-44299 can be found at the following reference: https://github.com/NavigateCMS/Navigate-CMS/issues/29