CVE-2021-26702 describes a reflected Cross-Site Scripting (XSS) vulnerability in EPrints version 3.4.2, specifically within the 'dataset' parameter of the cgi/dataset_dictionary URI. This medium-severity flaw (CVSS 6.1) requires user interaction and a network-based attack, potentially leading to limited impact on confidentiality and integrity. While no active exploitation or public exploit code (Metasploit, ExploitDB) has been identified, a Nuclei template exists, indicating some community awareness. There is minimal social media discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.4.2CPE matchmatch criteria | cpe:2.3:a:eprints:eprints:3.4.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.