Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Peithon

#47077of 53,624
5.4Total CVSS
Vulnerabilities · 1
PT-2021-20197
5.4
2021-02-24
Lightcms · Lightcms · CVE-2021-3355
**Name of the Vulnerable Software and Affected Versions** LightCMS version 1.3.4 **Description** A stored-self XSS issue exists, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to "/admin/SensitiveWords". **Recommendations** For LightCMS version 1.3.4, as a temporary workaround, consider restricting access to the "/admin/SensitiveWords" endpoint until a patch is available. Avoid using the vulnerable Title field in this endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.