Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Alex123-2Star

#47333of 53,630
5.4Total CVSS
Vulnerabilities · 1
PT-2021-21960
5.4
2021-08-05
Onenav · Onenav · CVE-2021-38138
Name of the Vulnerable Software and Affected Versions: OneNav beta version 0.9.12 Description: The issue allows for XSS via the Add Link feature. The vendor has stated that there is intentionally no XSS protection at present, as the attack risk is largely limited to a compromised account. However, XSS protection is planned for a future release. Recommendations: For OneNav beta version 0.9.12, consider disabling the Add Link feature until XSS protection is implemented in a future release.