CVE-2021-37596: XSS
Published Jul 27, 2021
·Updated
Telegram Web K Alpha 0.6.1 allows XSS via a document name.
Affected Software
1 affected component
Telegram Web K Alpha=0.6.1
Remediation
Event History
Jul 27, 2021
CVE Published
via MITRE·11:45 PM
Data Sourced
via MITRE·11:45 PM
Description
Jul 30, 2021
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-37596?
CVE-2021-37596 is a vulnerability in Telegram Web K Alpha 0.6.1 that allows XSS (Cross-Site Scripting) attacks via a document name.
2
How severe is CVE-2021-37596?
CVE-2021-37596 has a severity value of 6.1, which is considered medium severity.
3
How can the XSS vulnerability be exploited in Telegram Web K Alpha 0.6.1?
The XSS vulnerability in Telegram Web K Alpha 0.6.1 can be exploited by injecting malicious scripts into a document name.
4
Are all versions of Telegram Web K Alpha affected by CVE-2021-37596?
No, only version 0.6.1 of Telegram Web K Alpha is affected by CVE-2021-37596.
5
Is there a fix available for CVE-2021-37596?
Yes, a fix for CVE-2021-37596 is available in the code commit 11d2fe01363889f20c8baa2217ed4aad445c5551.