CVE-2021-26628 - CVE House
Back to Database
Status published High CVE-2021-26628

MaxBoard XSS and File Upload Vulnerability

Vulnerability Description

Insufficient script validation of the admin page enables XSS, which causes unauthorized users to steal admin privileges. When uploading file in a specific menu, the verification of the files is insufficient. It allows remote attackers to upload arbitrary files disguising them as image files.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-26628

Credits & Attribution

No credits recorded in the NVD database.