Medium severity5.4NVD Advisory· Published Apr 1, 2021· Updated Jun 17, 2026
CVE-2021-28047
CVE-2021-28047
Description
Cross-Site Scripting (XSS) in Administrative Reports in Devolutions Remote Desktop Manager before 2021.1 allows remote authenticated users to inject arbitrary web script or HTML via multiple input fields.
Affected products
3cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:*:*:*range: <2021.1.0
- (no CPE)range: <2021.1
- Devolutions/Remote Desktop Managerdescription
Patches
Vulnerability mechanics
References
1- devolutions.net/security/advisories/devo-2021-0003nvdVendor Advisory
News mentions
0No linked articles in our index yet.