S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-26702 Scanner

CVE-2021-26702 scanner - Cross-Site Scripting (XSS) vulnerability in EPrints

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-26702
6.1
CVSS

EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

EPrints is a widely used open-source software designed for building and managing digital repositories. It was developed by the University of Southampton's School of Electronics and Computer Science to facilitate the creation of online archives, such as institutional repositories, journals, and data repositories. The software provides a robust platform for storing, organizing, and distributing digital content, including documents, images, videos, and audio recordings. 

CVE-2021-26702 is a vulnerability that was discovered in EPrints 3.4.2. This vulnerability involves a reflected cross-site scripting (XSS) attack that can be exploited by an attacker to inject malicious code into a user's browser. This vulnerability occurs in the cgi/dataset_dictionary URI, specifically in the dataset parameter. This issue could allow an attacker to gain unauthorized access to sensitive information, including login credentials, personal data, and financial information.

When exploited, this vulnerability can have severe consequences for users and their digital assets. An attacker can use this vulnerability to steal sensitive information, including passwords, credit card information, and Social Security numbers, among others. They can then use this data to commit various forms of cybercrime, such as identity theft, financial fraud, and phishing attacks. Moreover, an attacker can use this vulnerability to spread malware and viruses, infecting other users' digital assets.

At s4e.io, we're committed to providing our clients with the latest information on digital vulnerabilities that can compromise their assets. With our pro features, users can quickly and efficiently identify and remediate vulnerabilities in their digital assets, protecting their data and privacy. Our platform provides a comprehensive suite of security tools and features, including vulnerability scans, penetration testing, and security assessments, to ensure that our clients are always up-to-date with the latest threats and risks. With s4e.io, you can rest assured that your digital assets are always secure.

 

REFERENCES

Solution Advice

Fortunately, there are several precautions that users can take to protect themselves against this vulnerability. Here are some of the recommended measures:

  • Update EPrints to the latest version to patch the vulnerability.
  • Block requests with malicious payloads using a web application firewall (WAF).
  • Filter user input to prevent script injection attacks using output encoding techniques.
  • Implement access controls to prevent unauthorized access to sensitive information.
  • Train employees and users on safe browsing habits, such as avoiding suspicious links and attachments in emails.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.