CVE-2021-30637: XSS
Published Apr 13, 2021
·Updated
htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.
Affected Software
1 affected component
Htmly Htmly=2.8.0
Event History
Apr 13, 2021
CVE Published
via MITRE·04:58 AM
Data Sourced
via MITRE·04:58 AM
Description
Frequently Asked Questions
1
What is CVE-2021-30637?
CVE-2021-30637 refers to a vulnerability in htmly 2.8.0 that allows for stored cross-site scripting (XSS) attacks via the blog title, Tagline, or Description to config.html.php.
2
How does CVE-2021-30637 affect htmly?
CVE-2021-30637 affects htmly 2.8.0.
3
What is the severity of CVE-2021-30637?
CVE-2021-30637 has a severity keyword of 'medium' and a severity value of 5.4.
4
How can I fix CVE-2021-30637?
To fix CVE-2021-30637, it is recommended to update htmly to a version that has addressed the vulnerability.
5
Are there any references related to CVE-2021-30637?
Yes, there are references available for CVE-2021-30637. They can be found at the following URLs: http://packetstormsecurity.com/files/162195/htmly-2.8.0-Cross-Site-Scripting.html and https://github.com/danpros/htmly/issues/456