CVE-2021-45919: XSS
Published Feb 8, 2022
·Updated
Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.
Affected Software
1 affected component
std42 elFinder<=2.1.31
Event History
Feb 8, 2022
CVE Published
via MITRE·10:27 PM
Data Sourced
via MITRE·10:27 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-45919?
CVE-2021-45919 is classified as a medium severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
2
How does CVE-2021-45919 affect my application?
CVE-2021-45919 affects applications using Studio 42 elFinder versions up to 2.1.31, allowing an attacker to inject malicious scripts via SVG documents.
3
How do I fix CVE-2021-45919?
To fix CVE-2021-45919, upgrade to elFinder version 2.1.32 or later, which includes a patch for the XSS vulnerability.
4
What are the potential risks of CVE-2021-45919 if not addressed?
If not addressed, CVE-2021-45919 could lead to unauthorized script execution, leading to data theft, session hijacking, or defacement of the web application.
5
Is CVE-2021-45919 a common vulnerability?
CVE-2021-45919 highlights a common web vulnerability type, XSS, which is frequently exploited in various web applications.