First published: Tue Aug 03 2021(Updated: )
The "content" field in the "regular post" page of the "add content" menu under "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerability. It allows remote attackers to send authenticated post-http requests to add / content and inject arbitrary web scripts or HTML through special content.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Htmly | =2.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-36702.
The severity of CVE-2021-36702 is medium.
The affected software is Htmly 2.8.1.
The CWE ID for CVE-2021-36702 is CWE-79.
Yes, you can find the reference link for CVE-2021-36702 [here](https://github.com/danpros/htmly/issues/481).