First published: Mon Sep 06 2021(Updated: )
bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Bookstackapp Bookstack | <21.08.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2021-3767.
The severity of CVE-2021-3767 is medium with a CVSS score of 5.4.
The affected software is Bookstack version up to and excluding 21.08.2.
This vulnerability in Bookstack allows for improper neutralization of input during web page generation, leading to cross-site scripting (XSS) attacks.
To fix CVE-2021-3767, you should update Bookstack to a version beyond 21.08.2.