CVE-2021-46871: XSS
Published Jan 10, 2023
·Updated
tag.ex in Phoenix Phoenix.HTML (aka phoenixhtml) before 3.0.4 allows XSS in HEEx class attributes.
Affected Software
1 affected component
phoenixframework Phoenix Html<3.0.4
Remediation
Patch Available
Event History
Jan 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-46871?
CVE-2021-46871 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2021-46871?
To fix CVE-2021-46871, upgrade your Phoenix.HTML library to version 3.0.4 or later.
3
What type of vulnerability is CVE-2021-46871?
CVE-2021-46871 is an XSS vulnerability found in HEEx class attributes within the Phoenix.HTML library.
4
Which versions of Phoenix.HTML are affected by CVE-2021-46871?
CVE-2021-46871 affects all versions of Phoenix.HTML prior to 3.0.4.
5
Can CVE-2021-46871 be exploited in a web application?
Yes, CVE-2021-46871 can be exploited to inject malicious scripts into web applications that use vulnerable versions of Phoenix.HTML.