Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-27902 - Vulnerability Database
Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-27902
Medium
Reference:
CVE-2021-27902
Title:
Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
An issue was discovered in Craft CMS before 3.6.0. In some circumstances a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.