First published: Thu Dec 23 2021(Updated: )
An XSS vulnerability was found in Privoxy which was fixed in cgi_error_no_template() by encode the template name when Privoxy is configured to servce the user-manual itself.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Privoxy Privoxy | <3.0.33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44543 is an XSS vulnerability found in Privoxy.
CVE-2021-44543 has a severity rating of 6.1, which is considered medium.
Privoxy versions up to and excluding 3.0.33 are affected by CVE-2021-44543.
CVE-2021-44543 was fixed in cgi_error_no_template() function by encoding the template name when Privoxy is configured to serve the user-manual itself.
You can find more information about CVE-2021-44543 on the Privoxy website: [https://www.privoxy.org/3.0.33/user-manual/whatsnew.html](https://www.privoxy.org/3.0.33/user-manual/whatsnew.html)