MEDIUM · 6.1

CVE-2021-46827

An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS vulnerability in search terms proposals (in online documentation generated usin...

Vulnerability Description

An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS vulnerability in search terms proposals (in online documentation generated using Oxygen XML WebHelp) allows attackers to execute JavaScript by convincing a user to type specific text in the WebHelp output search field.

CVSS Score

6.1

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
SyncOxygen Publishing Engine< 22.1
SyncOxygen Xml Author< 22.1
SyncOxygen Xml Developer< 22.1
SyncOxygen Xml Editor< 22.1
SyncOxygen Xml Webhelp< 22.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-46827?

CVE-2021-46827 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS vulnerability in search terms proposals (in online documentation generated usin...

How severe is CVE-2021-46827?

CVE-2021-46827 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-46827?

Check the references section above for vendor advisories and patch information. Affected products include: Sync Oxygen Publishing Engine, Sync Oxygen Xml Author, Sync Oxygen Xml Developer, Sync Oxygen Xml Editor, Sync Oxygen Xml Webhelp.