First published: Tue Aug 03 2021(Updated: )
The "blog title" field in the "Settings" menu "config" page of "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerability. It allows remote attackers to send an authenticated post HTTP request to admin/config and inject arbitrary web script or HTML through a special website name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Htmly | =2.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-36703.
The severity of CVE-2021-36703 is medium.
The affected software is Htmly version 2.8.1.
The CWE number for CVE-2021-36703 is CWE-79.
Yes, please refer to the reference link for information on how to fix CVE-2021-36703.