First published: Fri Feb 05 2021(Updated: )
LinkedIn Oncall through 1.4.0 allows reflected XSS via /query because of mishandling of the "No results found for" message in the search bar.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
LinkedIn Oncall | <=1.4.0 | |
pip/oncall | <1.4.1 | 1.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26722 is a vulnerability in LinkedIn Oncall through version 1.4.0 that allows reflected XSS via the /query endpoint.
The severity of CVE-2021-26722 is medium with a CVSS score of 6.1.
CVE-2021-26722 occurs due to mishandling of the "No results found for" message in the search bar of LinkedIn Oncall.
LinkedIn Oncall versions up to and including 1.4.0 are affected by CVE-2021-26722.
A fix for CVE-2021-26722 may be available in a future release of LinkedIn Oncall.