Vulnerability Description
An issue was discovered in JPress v3.3.0 and below. There are XSS vulnerabilities in the template module and tag management module. If you log in to the background by means of weak password, the storage XSS vulnerability can occur.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jpress | Jpress | <= 3.3.0 |
Related Weaknesses (CWE)
References
- https://github.com/JPressProjects/jpress/issues/152ExploitIssue TrackingThird Party Advisory
- https://github.com/JPressProjects/jpress/issues/152#issuecomment-850119847ExploitIssue TrackingThird Party Advisory
- https://github.com/JPressProjects/jpress/issues/152ExploitIssue TrackingThird Party Advisory
- https://github.com/JPressProjects/jpress/issues/152#issuecomment-850119847ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2021-33347?
CVE-2021-33347 is a vulnerability with a CVSS score of 5.4 (MEDIUM). An issue was discovered in JPress v3.3.0 and below. There are XSS vulnerabilities in the template module and tag management module. If you log in to the background by means of weak password, the stora...
How severe is CVE-2021-33347?
CVE-2021-33347 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-33347?
Check the references section above for vendor advisories and patch information. Affected products include: Jpress Jpress.