CVE-2021-38113 Information

Description

In addBouquet in js/bqe.js in OpenWebif (aka e2openplugin-OpenWebif) through 1.4.7 inserting JavaScript into the Add Bouquet feature of the Bouquet Editor (i.e. bouqueteditor/api/addbouquet?name=) leads to Stored XSS.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Reference

https://github.com/E2OpenPlugins/e2openplugin-OpenWebif/issues/1387

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

5.4

Share on: