ZeroHour

CVE-2021-33850

PoC
CVSS 3.1
5.4 medium
EPSS
2%p74
Published
()
Modified
Description

There is a Cross-Site Scripting vulnerability in Microsoft Clarity version 0.3. The XSS payload executes whenever the user changes the clarity configuration in Microsoft Clarity version 0.3. The payload is stored on the configuring project Id page.

Vendors
microsoft
Products
clarity
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.