VYPR

XpressEngine

by Xpressengine

CVEs (1)

  • CVE-2021-44912Feb 9, 2022
    risk 0.00cvss epss 0.00

    In XE 1.116, when uploading the Normal button, there is no restriction on the file suffix, which leads to any file uploading to the files directory. Since .htaccess only restricts the PHP type, uploading HTML-type files leads to stored XSS vulnerabilities. If the .htaccess…