CVE-2021-3271

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-3271
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3271.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-3271
Aliases
Published
2021-02-18T19:15:13Z
Modified
2024-05-14T08:46:40.825692Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

PressBooks 5.17.3 contains a cross-site scripting (XSS). Stored XSS can be submitted via the Book Info's Long Description Body, and all actions to open or preview the books page will result in the triggering the stored XSS.

References

Affected packages

Git / github.com/pressbooks/pressbooks

Affected ranges

Type
GIT
Repo
https://github.com/pressbooks/pressbooks
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

3.*

3.9.10
3.9.7.1
3.9.7.2
3.9.8
3.9.8-RC1
3.9.8-RC2
3.9.8-RC3
3.9.8.1
3.9.8.2
3.9.9

4.*

4.0.0
4.0.0-RC1
4.0.1
4.0.2
4.1.0
4.2.0
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.4.0
4.5.0
4.5.1

5.*

5.0.0
5.0.0-beta.1
5.0.0-rc.1
5.0.1
5.0.2
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.14.3
5.14.4
5.14.5
5.14.6
5.15.0
5.15.1
5.15.2
5.15.3
5.16.0
5.16.1
5.16.2
5.16.3
5.17.0
5.17.1
5.17.2
5.17.3
5.2.0
5.2.1
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
5.4.7
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.5.6
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.7.0
5.7.1
5.7.2
5.8.0
5.8.1
5.8.2
5.8.3
5.9.0
5.9.1
5.9.2
5.9.3
5.9.4
5.9.5

v2.*

v2.0.0
v2.0.1
v2.0.2
v2.2.0
v2.2.1
v2.3
v2.3.2
v2.3.3
v2.4
v2.4.1
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.5
v2.5.1
v2.5.2
v2.5.3
v2.5.4
v2.6
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.6.5
v2.6.6
v2.6.7
v2.7
v2.7.1
v2.7.2

v3.*

v3.0
v3.1
v3.1.1
v3.1.2
v3.2.0
v3.3.0
v3.3.1
v3.3.2
v3.4.0
v3.5.0
v3.5.1
v3.5.2
v3.6.0
v3.6.1
v3.6.2
v3.6.3
v3.7.0
v3.7.1
v3.8.0
v3.8.1
v3.9.0
v3.9.1
v3.9.2
v3.9.2.1
v3.9.3
v3.9.4
v3.9.4.1
v3.9.4.2
v3.9.5
v3.9.5.1
v3.9.6
v3.9.7
v3.9.7-RC1
v3.9.7-RC2
v3.9.7-RC3