CVE-2021-36702: XSS
Published Aug 3, 2021
·Updated
The "content" field in the "regular post" page of the "add content" menu under "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerability. It allows remote attackers to send authenticated post-http requests to add / content and inject arbitrary web scripts or HTML through special content.
Affected Software
1 affected component
Htmly Htmly=2.8.1
Event History
Aug 3, 2021
CVE Published
via MITRE·06:03 PM
Data Sourced
via MITRE·06:03 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-36702.
2
What is the severity of CVE-2021-36702?
The severity of CVE-2021-36702 is medium.
3
What is the affected software?
The affected software is Htmly 2.8.1.
4
What is the CWE ID for CVE-2021-36702?
The CWE ID for CVE-2021-36702 is CWE-79.
5
Is there a reference link for CVE-2021-36702?
Yes, you can find the reference link for CVE-2021-36702 [here](https://github.com/danpros/htmly/issues/481).