CVE-2021-32857: GHSL-2021-1035: Cross-Site Scripting (XXS) in Cockpit Next - CVE-2021-32857
Bad HTML sanitization in htmleditor.js may lead to cross-site scripting (XSS) issues.
Other sources
Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML sanitization in htmleditor.js may lead to cross-site scripting (XSS) issues. There are no known patches for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-32857?
CVE-2021-32857 is a vulnerability in the Cockpit content management system that allows for cross-site scripting (XSS) attacks.
What is the severity of CVE-2021-32857?
CVE-2021-32857 has a severity level of medium with a CVSS score of 6.1.
How does CVE-2021-32857 impact the Cockpit content management system?
CVE-2021-32857 can lead to cross-site scripting (XSS) issues in versions 0.12.2 and prior of Cockpit.
Are there any known patches for CVE-2021-32857?
No, there are currently no known patches for CVE-2021-32857.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-32857?
The CWE ID for CVE-2021-32857 is CWE-79, which is for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').