CVE-2021-36703: XSS
Published Aug 3, 2021
·Updated
The "blog title" field in the "Settings" menu "config" page of "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerability. It allows remote attackers to send an authenticated post HTTP request to admin/config and inject arbitrary web script or HTML through a special website name.
Affected Software
1 affected component
Htmly Htmly=2.8.1
Event History
Aug 3, 2021
CVE Published
via MITRE·06:03 PM
Data Sourced
via MITRE·06:03 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-36703.
2
What is the severity of CVE-2021-36703?
The severity of CVE-2021-36703 is medium.
3
What is the affected software?
The affected software is Htmly version 2.8.1.
4
What is the CWE number for CVE-2021-36703?
The CWE number for CVE-2021-36703 is CWE-79.
5
Is there a fix available for CVE-2021-36703?
Yes, please refer to the reference link for information on how to fix CVE-2021-36703.