Vulnerability Description
An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Craftcms | Craft Cms | < 3.6.0 |
Related Weaknesses (CWE)
References
- https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#360---2021-01-26Release NotesThird Party Advisory
- https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#security-1Release NotesThird Party Advisory
- https://github.com/craftcms/cms/commit/8ee85a8f03c143fa2420e7d6f311d95cae3b19cePatchThird Party Advisory
- https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#360---2021-01-26Release NotesThird Party Advisory
- https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#security-1Release NotesThird Party Advisory
- https://github.com/craftcms/cms/commit/8ee85a8f03c143fa2420e7d6f311d95cae3b19cePatchThird Party Advisory
FAQ
What is CVE-2021-27902?
CVE-2021-27902 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.
How severe is CVE-2021-27902?
CVE-2021-27902 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27902?
Check the references section above for vendor advisories and patch information. Affected products include: Craftcms Craft Cms.