← Back

CVE-2021-46827

nvd nist
Published: Jul 13, 2022Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS vulnerability in search terms proposals (in online documentation generated using Oxygen XML WebHelp) allows attackers to execute JavaScript by convincing a user to type specific text in the WebHelp output search field.

Affected (39)

5 products
Oxygen Publishing Engine
Oxygen Xml Author
Oxygen Xml Developer
Oxygen Xml Editor
Oxygen Xml Webhelp
Configuration A
39 vulnerable
Vulnerable SoftwareAffected Versions
Sync
Before 22.1
Version 22.1 2020061014
Version 22.1 2020072823
Version 22.1 2020100801
Version 22.1 2020121711
Version 23.1 2021040717
Version 23.1 2021060401
Sync
Before 22.1
Version 22.1 2020061102
Version 22.1 2020072902
Version 22.1 2020100710
Version 22.1 2020121713
Version 23.1 2021030206
Version 23.1 2021040908
Version 23.1 2021061407
Sync
Before 22.1
Version 22.1 2020061102
Version 22.1 2020072902
Version 22.1 2020100710
Version 22.1 2020121713
Version 23.1 2021030206
Version 23.1 2021040908
Version 23.1 2021061407
Sync
Before 22.1
Version 22.1 2020061102
Version 22.1 2020072902
Version 22.1 2020100710
Version 22.1 2020121713
Version 23.1 2021030206
Version 23.1 2021040908
Version 23.1 2021061407
Sync
Before 22.1
Version 22.1 2020061014
Version 22.1 2020072412
Version 22.1 2020100208
Version 22.1 2020121713
Version 23.1 2021030210
Version 23.1 2021040711
Version 23.1 2021060306

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.