CVE-2021-46372: XSS
Published Feb 18, 2022
·Updated
Scoold 1.47.2 is a Q&A/knowledge base platform written in Java. When writing a Q&A, the markdown editor is vulnerable to a XSS attack when using uppercase letters.
Affected Software
1 affected component
erudika scoold=1.47.2
Remediation
Event History
Feb 18, 2022
CVE Published
via MITRE·12:40 PM
Data Sourced
via MITRE·12:40 PM
Description
Frequently Asked Questions
1
What is CVE-2021-46372?
CVE-2021-46372 is a vulnerability in Scoold 1.47.2 that allows for a Cross-Site Scripting (XSS) attack when using uppercase letters in the markdown editor.
2
What is Scoold 1.47.2?
Scoold 1.47.2 is a Q&A/knowledge base platform written in Java.
3
How severe is CVE-2021-46372?
CVE-2021-46372 has a severity rating of medium with a score of 5.4.
4
How does CVE-2021-46372 affect Scoold?
CVE-2021-46372 affects Scoold 1.47.2 and allows for a XSS attack in the markdown editor.
5
Is there a fix for CVE-2021-46372?
As of now, there is no known fix for CVE-2021-46372. It is recommended to avoid using uppercase letters in the markdown editor.