CVE-2021-20848
Published on: 11/24/2021 12:00:00 AM UTC
Last Modified on: 11/26/2021 07:01:00 PM UTC
Certain versions of Rwtxt from Rwtxt Project contain the following vulnerability:
Cross-site scripting vulnerability in rwtxt versions prior to v1.8.6 allows a remote attacker to inject an arbitrary script via unspecified vectors.
- CVE-2021-20848 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Zack Scholl - rwtxt version versions prior to v1.8.6
CVSS3 Score: 6.1 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | NONE |
CVSS2 Score: 4.3 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | PARTIAL | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
GitHub - schollz/rwtxt: A cms for absolute minimalists. | github.com text/html |
![]() |
JVN#22515597: rwtxt vulnerable to cross-site scripting | jvn.jp text/xml |
![]() |
Related QID Numbers
- 980002 Go (go) Security Update for github.com/schollz/rwtxt (GHSA-458f-26r3-x2c3)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Rwtxt Project | Rwtxt | All | All | All | All |
- cpe:2.3:a:rwtxt_project:rwtxt:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-20848 : Cross-site scripting vulnerability in rwtxt versions prior to v1.8.6 allows a remote attacker to i… twitter.com/i/web/status/1… | 2021-11-24 10:45:43 |