CVE-2021-3427
Summary
| CVE | CVE-2021-3427 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-26 16:15:00 UTC |
| Updated | 2022-10-28 20:09:00 UTC |
| Description | The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torrent file can execute arbitrary Javascript code in the context of the user's browser session. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710644 Gentoo Linux Deluge Cross-Site Scripting Vulnerability (GLSA 202210-07)