Vulnerability Database
Blog
FAQ
Docs
CVE-2021-3137
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2021-3137
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3137.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-3137
Aliases
GHSA-43hg-g44q-474q
Published
2021-01-20T04:15:13Z
Modified
2024-09-02T22:12:04Z
Severity
5.4 (Medium)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS Calculator
Summary
[none]
Details
XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.
References
https://www.exploit-db.com/exploits/49437
Affected packages
Git
/
github.com/xwiki/xwiki-commons
Affected ranges
Type
GIT
Repo
https://github.com/xwiki/xwiki-commons
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Last affected
afc3a117997a7a10595deb42279020817d7e8df8
Type
GIT
Repo
https://github.com/xwiki/xwiki-platform
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Last affected
41b9b4028ed205559c15778fa630eec6a15496d4
CVE-2021-3137 - OSV