CVE-2021-3150
6.1 MEDIUMA cross-site scripting (XSS) vulnerability on the Delete Personal Data page in Cryptshare Server before 4.8.0 allows an attacker to injec...
Published: 2021-03-15 · Last updated: 2026-06-17
Severity and scoring
- CVSS
- 6.1 MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- CWE
- CWE-79
Affected products
| Vendor | Product |
|---|---|
| cryptshare | cryptshare_server |
Description
A cross-site scripting (XSS) vulnerability on the Delete Personal Data page in Cryptshare Server before 4.8.0 allows an attacker to inject arbitrary web script or HTML via the user name. The issue is fixed with the version 4.8.1
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2021-3150
- [Other]https://kc.mcafee.com/corporate/index?page=content&id=SB10356
- [Vendor advisory]https://wiki.cryptshare.com/display/CSM/Update+from+v4.7.1+to+v4.8.1
- [Other]https://kc.mcafee.com/corporate/index?page=content&id=SB10356
- [Vendor advisory]https://wiki.cryptshare.com/display/CSM/Update+from+v4.7.1+to+v4.8.1
Related CVEs
Same CWE
- CVE-2026-12425 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access ...
- CVE-2024-30476 — PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager (5.4 MEDIUM)
- CVE-2026-54198 — Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions (7.1 HIGH)
- CVE-2026-54191 — Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions (7.1 HIGH)
- CVE-2026-39437 — Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions (7.1 HIGH)