VYPR
Medium severity6.5NVD Advisory· Published Apr 14, 2021· Updated Jun 17, 2026

CVE-2021-28048

CVE-2021-28048

Description

An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows a remote attacker to leak cross-origin data via a crafted HTML page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Devolutions/Devolutions Serverdescription
  • cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:lts:*:*:*+ 2 more
    • cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:lts:*:*:*range: <2020.3.18
    • cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:-:*:*:*range: <2021.1
    • (no CPE)range: <2021.1, <2020.3.18

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.