First published: Tue Jul 27 2021(Updated: )
Telegram Web K Alpha 0.6.1 allows XSS via a document name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Telegram Web K Alpha | =0.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37596 is a vulnerability in Telegram Web K Alpha 0.6.1 that allows XSS (Cross-Site Scripting) attacks via a document name.
CVE-2021-37596 has a severity value of 6.1, which is considered medium severity.
The XSS vulnerability in Telegram Web K Alpha 0.6.1 can be exploited by injecting malicious scripts into a document name.
No, only version 0.6.1 of Telegram Web K Alpha is affected by CVE-2021-37596.
Yes, a fix for CVE-2021-37596 is available in the code commit 11d2fe01363889f20c8baa2217ed4aad445c5551.