Medium severity5.4NVD Advisory· Published Dec 24, 2021· Updated Jun 17, 2026
CVE-2021-4072
CVE-2021-4072
Description
elgg is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
elgg/elggPackagist | < 3.3.24 | 3.3.24 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/elgg/elgg/commit/c30b17bf75256ed3fcc84e2083147cc3951423d0nvdPatchThird Party AdvisoryWEB
- huntr.dev/bounties/74034253-732a-4251-a0f9-eca5f576c955nvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-2xw8-j43j-5vxpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-4072ghsaADVISORY
News mentions
0No linked articles in our index yet.