Vulnerability Description
In addBouquet in js/bqe.js in OpenWebif (aka e2openplugin-OpenWebif) through 1.4.7, inserting JavaScript into the Add Bouquet feature of the Bouquet Editor (i.e., bouqueteditor/api/addbouquet?name=) leads to Stored XSS.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openwebif Project | Openwebif | <= 1.4.7 |
Related Weaknesses (CWE)
References
- https://github.com/E2OpenPlugins/e2openplugin-OpenWebif/issues/1387ExploitIssue TrackingPatch
- https://github.com/E2OpenPlugins/e2openplugin-OpenWebif/issues/1387ExploitIssue TrackingPatch
FAQ
What is CVE-2021-38113?
CVE-2021-38113 is a vulnerability with a CVSS score of 5.4 (MEDIUM). In addBouquet in js/bqe.js in OpenWebif (aka e2openplugin-OpenWebif) through 1.4.7, inserting JavaScript into the Add Bouquet feature of the Bouquet Editor (i.e., bouqueteditor/api/addbouquet?name=) l...
How severe is CVE-2021-38113?
CVE-2021-38113 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-38113?
Check the references section above for vendor advisories and patch information. Affected products include: Openwebif Project Openwebif.