Back to Database
Status published
Medium
CVE-2021-28977
Cross Site Scripting vulnerability in GetSimpleCMS 3.3.16 in admin/upload.php by...
Vulnerability Description
Cross Site Scripting vulnerability in GetSimpleCMS 3.3.16 in admin/upload.php by adding comments or jpg and other file header information to the content of xla, pages, and gzip files,
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-28977
Credits & Attribution
No credits recorded in the NVD database.
More from get-simple
View All →CVE-2022-41544
GetSimple CMS v3.3.16 was discovered to contain a remote code...
Unknown
0
CVE-2021-36601
GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function...
Medium
6.1
CVE-2021-28976
Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php...
High
7.2
CVE-2020-24861
GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings...
Medium
5.4
CVE-2020-23839
A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16,...
Medium
6.1
Affected Vendor
get-simple
View all reports →Affected Software
getsimplecms
Vulnerable Versions:
0
Timeline
Official Publish:
June 23rd, 2021
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.