CVE-2021-29663

MEDIUMCVSS 4.8/10EPSS 0.81%

Last modified

CVE-2021-29663 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. CourseMS (aka Course Registration Management System) 2.1 is affected by cross-site scripting (XSS). When an attacker with access to an Admin account creates a Job Title in the Site area (aka the admin/add_jobs.php name parameter), they can insert an XSS payload. EPSS estimates a 0.81% chance of exploitation in the next 30 days.

Description

CourseMS (aka Course Registration Management System) 2.1 is affected by cross-site scripting (XSS). When an attacker with access to an Admin account creates a Job Title in the Site area (aka the admin/add_jobs.php name parameter), they can insert an XSS payload. This payload will execute whenever anyone visits the registration page.

Metrics

CVSS 3.1
4.8/10

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

EPSS Probability
0.81%

52.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Course Registration Management System ProjectCourse Registration Management System2.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-29663?
CourseMS (aka Course Registration Management System) 2.1 is affected by cross-site scripting (XSS). When an attacker with access to an Admin account creates a Job Title in the Site area (aka the admin/add_jobs.php name parameter), they can insert an XSS payload. This payload will execute whenever anyone visits the registration page.
How severe is CVE-2021-29663?
CVE-2021-29663 has a CVSS score of 4.8/10 (MEDIUM severity). The EPSS model estimates a 0.81% probability of exploitation in the next 30 days.
How do I fix CVE-2021-29663?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-29663?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST