Unknown · Omeka Classic · CVE-2021-26799
**Name of the Vulnerable Software and Affected Versions**
Omeka Classic versions <=2.7
**Description**
The issue allows remote attackers to inject arbitrary web script or HTML via the admin/files/edit endpoint. This is a Cross Site Scripting (XSS) issue.
**Recommendations**
For Omeka Classic versions <=2.7, update to a version greater than 2.7 to resolve the issue.
As a temporary workaround, consider restricting access to the admin/files/edit endpoint until a patch is available.