CVE-2021-44543: XSS
Published Dec 23, 2021
·Updated
An XSS vulnerability was found in Privoxy which was fixed in cgierrornotemplate() by encode the template name when Privoxy is configured to servce the user-manual itself.
Affected Software
1 affected component
Privoxy privoxy<3.0.33
Remediation
Event History
Dec 23, 2021
CVE Published
via MITRE·07:48 PM
Data Sourced
via MITRE·07:48 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-44543?
CVE-2021-44543 is an XSS vulnerability found in Privoxy.
2
How severe is CVE-2021-44543?
CVE-2021-44543 has a severity rating of 6.1, which is considered medium.
3
What software versions are affected by CVE-2021-44543?
Privoxy versions up to and excluding 3.0.33 are affected by CVE-2021-44543.
4
How was CVE-2021-44543 fixed?
CVE-2021-44543 was fixed in cgi_error_no_template() function by encoding the template name when Privoxy is configured to serve the user-manual itself.
5
Where can I find more information about CVE-2021-44543?
You can find more information about CVE-2021-44543 on the Privoxy website: [https://www.privoxy.org/3.0.33/user-manual/whatsnew.html](https://www.privoxy.org/3.0.33/user-manual/whatsnew.html)