VulnerabilityModified
CVE-2021-31330
A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier.
MEDIUM 5.4EPSS 0.81%
Does this matter?
Lower severity and a low EPSS score (0.81%). Track it; it rarely justifies an emergency change on its own.
Description
A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authenticated attacker may inject malicious Javascript code when using Markdown editing within the application which remains persistent.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.81% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- reviewboard/review board
- Source
- cve@mitre.org
References
- https://mattschmidt.net/2021/04/14/review-board-xss-discovered/Exploit, Third Party Advisory
- https://www.reviewboard.org/docs/releasenotes/reviewboard/3.0.21/Release Notes, Vendor Advisory
- https://www.reviewboard.org/docs/releasenotes/reviewboard/4.0-rc-2/Release Notes, Vendor Advisory
- https://www.reviewboard.org/news/2021/04/14/review-board-3-0-21-and-4-0-rc-2-security-bug-fixes-and-docker/Release Notes, Vendor Advisory
- https://mattschmidt.net/2021/04/14/review-board-xss-discovered/Exploit, Third Party Advisory
- https://www.reviewboard.org/docs/releasenotes/reviewboard/3.0.21/Release Notes, Vendor Advisory
- https://www.reviewboard.org/docs/releasenotes/reviewboard/4.0-rc-2/Release Notes, Vendor Advisory
- https://www.reviewboard.org/news/2021/04/14/review-board-3-0-21-and-4-0-rc-2-security-bug-fixes-and-docker/Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.