Lucene search

K
osvGoogleOSV:CVE-2021-27938
HistoryMar 16, 2021 - 4:15 p.m.

CVE-2021-27938

2021-03-1616:15:14
Google
osv.dev
4
vulnerability
silverstripe cms
cross site scripting
symbiote
queued jobs

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

29.3%

A vulnerability has been identified in the Silverstripe CMS 3 and 4 version of the symbiote/silverstripe-queuedjobs module. A Cross Site Scripting vulnerability allows an attacker to inject an arbitrary payload in the CreateQueuedJobTask dev task via a specially crafted URL.

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

29.3%