Medium severity4.8NVD Advisory· Published Feb 16, 2021· Updated Jun 17, 2026
CVE-2021-27237
CVE-2021-27237
Description
The admin panel in BlackCat CMS 1.3.6 allows stored XSS (by an admin) via the Display Name field to backend/preferences/ajax_save.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:blackcat-cms:blackcat_cms:1.3.6:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:blackcat-cms:blackcat_cms:1.3.6:*:*:*:*:*:*:*
- (no CPE)range: <=1.3.6
- BlackCat/CMSdescription
- Range: <=1.3.6
Patches
Vulnerability mechanics
References
3- github.com/BlackCatDevelopment/BlackCatCMS/commits/release-1.4/upload/backend/preferences/ajax_save.phpnvdPatchThird Party Advisory
- github.com/BlackCatDevelopment/BlackCatCMS/compare/1.3.6...1.4BetanvdPatchThird Party Advisory
- www.exploit-db.com/exploits/49565nvdExploitThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.