CVE-2021-32858

esdoc-publish-html-plugin is a plugin for the document maintenance software ESDoc. TheHTML sanitizer in esdoc-publish-html-plugin 1.1.2 and prior can be bypassed which may lead to cross-site scripting (XSS) issues. There are no known patches for this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:esdoc:esdoc-publish-html-plugin:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-02-21 15:15

Updated : 2024-02-28 19:51


NVD link : CVE-2021-32858

Mitre link : CVE-2021-32858

CVE.ORG link : CVE-2021-32858


JSON object : View

Products Affected

esdoc

  • esdoc-publish-html-plugin
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')