Vulnerability Description
A vulnerability was found in MyEMS up to 6.4.0. The affected element is the function on_post of the file myems-api/core/svg.py of the component Admin Backend. The manipulation of the argument new_values['data'] results in cross site scripting. The attack can be launched remotely. The exploit has been made public and could be used. Upgrading to version 6.5.0 is sufficient to fix this issue. The patch is identified as 4a97edfbd786c779d0322054833b21ddf54d5b06. It is suggested to upgrade the affected component. The issue report remains open even though there is an official fix for it.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/MyEMS/myems/
- https://github.com/MyEMS/myems/commit/4a97edfbd786c779d0322054833b21ddf54d5b06
- https://github.com/MyEMS/myems/issues/412
- https://github.com/MyEMS/myems/releases/tag/v6.5.0
- https://vuldb.com/cve/CVE-2026-15321
- https://vuldb.com/submit/853060
- https://vuldb.com/vuln/377263
- https://vuldb.com/vuln/377263/cti
- https://vuldb.com/submit/853060
FAQ
What is CVE-2026-15321?
CVE-2026-15321 is a vulnerability with a CVSS score of 2.4 (LOW). A vulnerability was found in MyEMS up to 6.4.0. The affected element is the function on_post of the file myems-api/core/svg.py of the component Admin Backend. The manipulation of the argument new_valu...
How severe is CVE-2026-15321?
CVE-2026-15321 has been rated LOW with a CVSS base score of 2.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-15321?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.