CVE-2021-44607: XSS
A Cross Site Scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 in the Assets page via an SVG file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-44607?
CVE-2021-44607 is a Cross Site Scripting (XSS) vulnerability that exists in FUEL-CMS 1.5.1 in the Assets page via an SVG file.
What is the severity of CVE-2021-44607?
The severity of CVE-2021-44607 is medium, with a CVSS score of 5.4.
How does CVE-2021-44607 impact FUEL-CMS?
CVE-2021-44607 allows an attacker to inject malicious scripts into the FUEL-CMS Assets page via an SVG file, potentially leading to arbitrary code execution or the theft of sensitive information.
How can I fix the CVE-2021-44607 vulnerability?
To fix the CVE-2021-44607 vulnerability, it is recommended to upgrade to a patched version of FUEL-CMS that addresses the Cross Site Scripting (XSS) vulnerability.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-44607?
The Common Weakness Enumeration (CWE) ID for CVE-2021-44607 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').