S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-26475 Scanner

CVE-2021-26475 scanner - Cross-Site Scripting (XSS) vulnerability in EPrints

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-26475
6.1
CVSS

EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

EPrints is an open-source software used primarily for building digital repositories. The software was initially developed by the University of Southampton in the early 2000s to help researchers manage their research data and publications. EPrints has since been widely used by universities, research institutions, and other organizations to create digital archives, institutional repositories, and research repositories.

One such vulnerability that has been detected in EPrints is the CVE-2021-26475 vulnerability. This vulnerability allows for a reflected XSS opportunity through the cgi/cal URI, which can be exploited by attackers to inject malicious code into web pages viewed by unsuspecting users. This vulnerability is particularly dangerous because it can be used to steal sensitive information from users or even take control of their machines.

If this vulnerability is exploited, it can lead to various cyber-attacks and security breaches. Attackers can execute malicious scripts to steal sensitive data, credentials, or other personal information that can eventually be used for identity theft, financial fraud, or even physical harm. Furthermore, attackers can use these malicious scripts to gain unauthorized access to the targeted systems and infect them with malicious software that can cause significant damages.

At s4e.io, our platform's pro features enable users to identify potential security threats in their digital assets quickly. Through our comprehensive vulnerability scanning and testing programs, users can easily and quickly learn about vulnerabilities in their digital assets and effectively mitigate them. By subscribing to our pro features, users can be sure that their digital repositories are safe and secure, now and in the future.

 

REFERENCES

Solution Advice

To protect EPrints digital repositories from CVE-2021-26475 vulnerability, several precautions can be taken, including:

  • Patching the Software: The first step in mitigating this vulnerability is to patch the EPrints software to the latest version. This will eliminate any known vulnerabilities and ensure that the system is up to date with the latest security patches.
  • Implementing Web Application Firewall (WAF): A WAF can be deployed to intercept and block known malicious requests and prevent them from reaching the EPrints web application.
  • Network Segmentation: Limiting network access to the digital repository that is running EPrints software is important. Limiting access prevents unauthorized access to the system.
  • Regular Scanning of Digital Assets: Regular scans of EPrints digital repositories ensure that vulnerabilities are quickly identified and fixed before they can be exploited.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-26475 scanner - Cross-Site Scripting (XSS) vulnerability in EPrints | S4E