6.1

CVE-2021-46827

An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS vulnerability in search terms proposals (in online documentation generated using Oxygen XML WebHelp) allows attackers to execute JavaScript by convincing a user to type specific text in the WebHelp output search field.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SyncOxygen Publishing Engine Version < 22.1
SyncOxygen Publishing Engine Version22.1 Update2020061014
SyncOxygen Publishing Engine Version22.1 Update2020072823
SyncOxygen Publishing Engine Version22.1 Update2020100801
SyncOxygen Publishing Engine Version22.1 Update2020121711
SyncOxygen Publishing Engine Version23.1 Update2021040717
SyncOxygen Publishing Engine Version23.1 Update2021060401
SyncOxygen Xml Author Version < 22.1
SyncOxygen Xml Author Version22.1 Update2020061102
SyncOxygen Xml Author Version22.1 Update2020072902
SyncOxygen Xml Author Version22.1 Update2020100710
SyncOxygen Xml Author Version22.1 Update2020121713
SyncOxygen Xml Author Version23.1 Update2021030206
SyncOxygen Xml Author Version23.1 Update2021040908
SyncOxygen Xml Author Version23.1 Update2021061407
SyncOxygen Xml Developer Version < 22.1
SyncOxygen Xml Developer Version22.1 Update2020061102
SyncOxygen Xml Developer Version22.1 Update2020072902
SyncOxygen Xml Developer Version22.1 Update2020100710
SyncOxygen Xml Developer Version22.1 Update2020121713
SyncOxygen Xml Developer Version23.1 Update2021030206
SyncOxygen Xml Developer Version23.1 Update2021040908
SyncOxygen Xml Developer Version23.1 Update2021061407
SyncOxygen Xml Editor Version < 22.1
SyncOxygen Xml Editor Version22.1 Update2020061102
SyncOxygen Xml Editor Version22.1 Update2020072902
SyncOxygen Xml Editor Version22.1 Update2020100710
SyncOxygen Xml Editor Version22.1 Update2020121713
SyncOxygen Xml Editor Version23.1 Update2021030206
SyncOxygen Xml Editor Version23.1 Update2021040908
SyncOxygen Xml Editor Version23.1 Update2021061407
SyncOxygen Xml Webhelp Version < 22.1
SyncOxygen Xml Webhelp Version22.1 Update2020061014
SyncOxygen Xml Webhelp Version22.1 Update2020072412
SyncOxygen Xml Webhelp Version22.1 Update2020100208
SyncOxygen Xml Webhelp Version22.1 Update2020121713
SyncOxygen Xml Webhelp Version23.1 Update2021030210
SyncOxygen Xml Webhelp Version23.1 Update2021040711
SyncOxygen Xml Webhelp Version23.1 Update2021060306
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.67% 0.71
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.