PT-2021-20231 · Vaadin · Vaadin+1
Published
2021-11-02
·
Updated
2021-11-03
·
CVE-2021-33611
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
org.webjars.bowergithub.vaadin:vaadin-menu-bar versions 1.0.0 through 1.2.0
Vaadin versions 14.0.0 through 14.4.4
Description:
The issue is related to missing output sanitization in test sources, allowing remote attackers to execute malicious JavaScript in a browser by opening a crafted URL.
Recommendations:
For org.webjars.bowergithub.vaadin:vaadin-menu-bar versions 1.0.0 through 1.2.0, update to a version outside of the affected range to resolve the issue.
For Vaadin versions 14.0.0 through 14.4.4, update to a version outside of the affected range to resolve the issue.
Exploit
Fix
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vaadin
Vaadin-Menu-Bar