CVE-2021-34817: XSS
Published Jul 19, 2021
·Updated
A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary JavaScript or HTML by importing a crafted pad.
Affected Software
1 affected component
Etherpad Etherpad=1.8.13
Remediation
Patch Available
Patch Available
Event History
Jul 19, 2021
CVE Published
via MITRE·01:38 PM
Data Sourced
via MITRE·01:38 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-34817.
2
What is the severity of CVE-2021-34817?
The severity of CVE-2021-34817 is medium, with a severity value of 6.1.
3
What is the affected software?
The affected software is Etherpad version 1.8.13.
4
How can remote attackers exploit CVE-2021-34817?
Remote attackers can exploit CVE-2021-34817 by injecting arbitrary JavaScript or HTML into the chat component of Etherpad 1.8.13.
5
Are there any fixes available for CVE-2021-34817?
Yes, updates and patches are available for Etherpad. Please refer to the official website or the GitHub repository for more information.