ZeroHour

CVE-2021-31330

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p55
Published
()
Modified
Description

A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authenticated attacker may inject malicious Javascript code when using Markdown editing within the application which remains persistent.

Vendors
reviewboard
Products
review board
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.