CVE-2021-31330Cross-site Scripting in Review Board

Severity
5.4MEDIUMNVD
EPSS
0.6%
top 30.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 11
Latest updateMay 12

Description

A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authenticated attacker may inject malicious Javascript code when using Markdown editing within the application which remains persistent.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages1 packages

NVDreviewboard/review_board3.0.20, 4.0+1

🔴Vulnerability Details

1
GHSA
GHSA-mhg9-m5gc-hhqw: A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 32022-05-12