CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.1. It may be remotely exploitable.
CVE
CVE-2021-26628
Severity
HIGH
CVSS
8.1
EPSS
0.76%
Original NVD Description
Insufficient script validation of the admin page enables XSS, which causes unauthorized users to steal admin privileges. When uploading file in a specific menu, the verification of the files is insufficient. It allows remote attackers to upload arbitrary files disguising them as image files.
Related CVEs
Other vulnerabilities affecting the same vendor(s)