First published: Wed May 11 2022(Updated: )
A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authenticated attacker may inject malicious Javascript code when using Markdown editing within the application which remains persistent.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Review Board | =3.0.20 | |
Review Board | =4.0-beta1 | |
Review Board | =4.0-beta2 | |
Review Board | =4.0-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31330 is considered a medium severity Cross-Site Scripting (XSS) vulnerability.
To fix CVE-2021-31330, upgrade to Review Board version 3.0.21 or later, or 4.0 RC2 or later.
CVE-2021-31330 affects users of Review Board versions 3.0.20 and any 4.0 beta and release candidate prior to 4.0 RC2.
CVE-2021-31330 is a Cross-Site Scripting (XSS) vulnerability.
An attacker can inject persistent malicious Javascript code into the application through Markdown editing.