Back to Database
Status published
Medium
CVE-2021-27237
The admin panel in BlackCat CMS 1.3.6 allows stored XSS...
Vulnerability Description
The admin panel in BlackCat CMS 1.3.6 allows stored XSS (by an admin) via the Display Name field to backend/preferences/ajax_save.php.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-27237
Credits & Attribution
No credits recorded in the NVD database.
References
More from blackcat-cms
View All →CVE-2023-53892
Blackcat CMS 1.4 Remote Code Execution via Jquery Plugin Manager
High
8.6
CVE-2023-53891
Blackcat CMS 1.4 Stored Cross-Site Scripting via Page Modification
Medium
5.1
CVE-2020-25878
A stored cross site scripting (XSS) vulnerability in the 'Admin-Tools'...
Medium
4.8
CVE-2020-25877
A stored cross site scripting (XSS) vulnerability in the 'Add...
Medium
5.4
CVE-2020-25453
An issue was discovered in BlackCat CMS before 1.4. There...
High
8.8
Affected Vendor
blackcat-cms
View all reports →Affected Software
blackcat cms
Vulnerable Versions:
1.3.6
Timeline
Official Publish:
February 16th, 2021
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.