CVE-2021-27695 describes multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT versions 2.1 through 3.3-b. Attackers can inject malicious web scripts or HTML into various "Add" sections, specifically through the Name and Code parameters. Rated as Medium severity (CVSS 6.1), this vulnerability requires user interaction (UI:R) but can be exploited remotely (AV:N) with low attack complexity (AC:L), potentially leading to limited impact on confidentiality and integrity. While not actively exploited in the wild and lacking Metasploit or Nuclei modules, an ExploitDB entry (EDB-49649) confirms exploit code availability, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.1-3.3-bCPE matchmatch criteria | cpe:2.3:a:openmaint:openmaint:2.1-3.3-b:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.