CVE-2021-23260

NameCVE-2021-23260
DescriptionAuthenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and other users of the same site.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Notes

NOT-FOR-US: Crafter CMS

Search for package or bug name: Reporting problems