PT-2022-9428 · Crow · Crow

Published

2022-01-13

·

Updated

2022-01-19

·

CVE-2021-23824

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Crow versions prior to 0.3+4
Description The issue affects the Crow package when attributes are used without quotes in the template. An attacker can manipulate the input to introduce additional attributes, potentially executing code, which may lead to a Cross-site Scripting (XSS) vulnerability. If the template is used to render user-generated content, this vulnerability may escalate to a persistent XSS vulnerability.
Recommendations For Crow versions prior to 0.3+4, consider using quotes for attributes in the template to prevent the introduction of additional attributes. As a temporary workaround, restrict the use of user-generated content in templates until a patch is available. Avoid using the template to render untrusted input until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23824
SNYK-UNMANAGED-CROW-2336164

Affected Products

Crow