VYPR
Medium severity5.4NVD Advisory· Published Sep 15, 2021· Updated Jun 17, 2026

CVE-2021-28901

CVE-2021-28901

Description

Multiple cross-site scripting (XSS) vulnerabilities exist in SITA Software Azur CMS 1.2.3.1 and earlier, which allows remote attackers to inject arbitrary web script or HTML via the (1) NOM_CLI , (2) ADRESSE , (3) ADRESSE2, (4) LOCALITE parameters to /eshop/products/json/aouCustomerAdresse; and the (5) nom_liste parameter to /eshop/products/json/addCustomerFavorite.

Affected products

3
  • cpe:2.3:a:sitasoftware:azurcms:*:*:*:*:*:*:*:*
    Range: <=1.2.3.12
  • SITA Software/Azur CMSdescription
  • Sita/AzurCMSllm-create
    Range: <=1.2.3.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.