VYPR
Medium severity6.1NVD Advisory· Published Mar 2, 2021· Updated Jun 17, 2026

CVE-2021-27888

CVE-2021-27888

Description

ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • Zend/Zendto4 versions
    cpe:2.3:a:zend:zendto:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:zend:zendto:*:*:*:*:*:*:*:*range: <=6.05-4
    • cpe:2.3:a:zend:zendto:6.06-1:beta:*:*:*:*:*:*
    • cpe:2.3:a:zend:zendto:6.06-2:beta:*:*:*:*:*:*
    • cpe:2.3:a:zend:zendto:6.06-3:beta:*:*:*:*:*:*
  • ZendTo/ZendTodescription
  • Zendto/Zendtollm-fuzzy
    Range: <6.06-4 Beta

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.