Openmaint · Openmaint · CVE-2021-27695
Name of the Vulnerable Software and Affected Versions:
openMAINT versions 2.1 through 3.3-b
Description:
The issue allows remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the `Name` and `Code` Parameters. This is a stored cross-site scripting (XSS) issue.
Recommendations:
For openMAINT versions 2.1 through 3.3-b, as a temporary workaround, consider restricting access to the "Add" sections until a patch is available. Avoid using the `Name` and `Code` parameters in the affected sections until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.