Vulnerability Description
The aimeos (aka Aimeos shop and e-commerce framework) extension before 19.10.12 and 20.x before 20.10.5 for TYPO3 allows XSS via a backend user account.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aimeos Project | Aimeos | < 19.10.12 |
Related Weaknesses (CWE)
References
- https://typo3.org/security/advisory/typo3-ext-sa-2021-003PatchVendor Advisory
- https://typo3.org/security/advisory/typo3-ext-sa-2021-003PatchVendor Advisory
FAQ
What is CVE-2021-28380?
CVE-2021-28380 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The aimeos (aka Aimeos shop and e-commerce framework) extension before 19.10.12 and 20.x before 20.10.5 for TYPO3 allows XSS via a backend user account.
How severe is CVE-2021-28380?
CVE-2021-28380 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-28380?
Check the references section above for vendor advisories and patch information. Affected products include: Aimeos Project Aimeos.