CVE-2021-3780: Cross-site Scripting (XSS) - Stored in chocobozzz/peertube
Published Sep 15, 2021
·Updated
peertube is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected Software
1 affected component
Framasoft Peertube<3.4.0
Remediation
Event History
Sep 15, 2021
CVE Published
via MITRE·11:15 AM
Data Sourced
via MITRE·11:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-3780?
CVE-2021-3780 has been classified as a medium severity vulnerability due to its potential for exploiting Cross-site Scripting.
2
How do I fix CVE-2021-3780?
To fix CVE-2021-3780, update your PeerTube instance to version 3.4.0 or later.
3
What versions of PeerTube are affected by CVE-2021-3780?
CVE-2021-3780 affects versions of PeerTube prior to 3.4.0.
4
What kind of vulnerability is CVE-2021-3780?
CVE-2021-3780 is a Cross-site Scripting vulnerability resulting from improper input neutralization during web page generation.
5
Is CVE-2021-3780 easily exploitable?
CVE-2021-3780 can be exploited by an attacker to inject malicious scripts into web pages viewed by users.