CVE-2021-46827
Summary
| CVE | CVE-2021-46827 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-13 05:15:00 UTC |
| Updated | 2022-07-20 14:00:00 UTC |
| Description | An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS vulnerability in search terms proposals (in online documentation generated using Oxygen XML WebHelp) allows attackers to execute JavaScript by convincing a user to type specific text in the WebHelp output search field. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sync | Oxygen Publishing Engine | All | All | All | All |
| Application | Sync | Oxygen Publishing Engine | 22.1 | 2020061014 | All | All |
| Application | Sync | Oxygen Publishing Engine | 22.1 | 2020072823 | All | All |
| Application | Sync | Oxygen Publishing Engine | 22.1 | 2020100801 | All | All |
| Application | Sync | Oxygen Publishing Engine | 22.1 | 2020121711 | All | All |
| Application | Sync | Oxygen Publishing Engine | 23.1 | 2021040717 | All | All |
| Application | Sync | Oxygen Publishing Engine | 23.1 | 2021060401 | All | All |
| Application | Sync | Oxygen Xml Author | All | All | All | All |
| Application | Sync | Oxygen Xml Author | 22.1 | 2020061102 | All | All |
| Application | Sync | Oxygen Xml Author | 22.1 | 2020072902 | All | All |
| Application | Sync | Oxygen Xml Author | 22.1 | 2020100710 | All | All |
| Application | Sync | Oxygen Xml Author | 22.1 | 2020121713 | All | All |
| Application | Sync | Oxygen Xml Author | 23.1 | 2021030206 | All | All |
| Application | Sync | Oxygen Xml Author | 23.1 | 2021040908 | All | All |
| Application | Sync | Oxygen Xml Author | 23.1 | 2021061407 | All | All |
| Application | Sync | Oxygen Xml Developer | All | All | All | All |
| Application | Sync | Oxygen Xml Developer | 22.1 | 2020061102 | All | All |
| Application | Sync | Oxygen Xml Developer | 22.1 | 2020072902 | All | All |
| Application | Sync | Oxygen Xml Developer | 22.1 | 2020100710 | All | All |
| Application | Sync | Oxygen Xml Developer | 22.1 | 2020121713 | All | All |
| Application | Sync | Oxygen Xml Developer | 23.1 | 2021030206 | All | All |
| Application | Sync | Oxygen Xml Developer | 23.1 | 2021040908 | All | All |
| Application | Sync | Oxygen Xml Developer | 23.1 | 2021061407 | All | All |
| Application | Sync | Oxygen Xml Editor | All | All | All | All |
| Application | Sync | Oxygen Xml Editor | 22.1 | 2020061102 | All | All |
| Application | Sync | Oxygen Xml Editor | 22.1 | 2020072902 | All | All |
| Application | Sync | Oxygen Xml Editor | 22.1 | 2020100710 | All | All |
| Application | Sync | Oxygen Xml Editor | 22.1 | 2020121713 | All | All |
| Application | Sync | Oxygen Xml Editor | 23.1 | 2021030206 | All | All |
| Application | Sync | Oxygen Xml Editor | 23.1 | 2021040908 | All | All |
| Application | Sync | Oxygen Xml Editor | 23.1 | 2021061407 | All | All |
| Application | Sync | Oxygen Xml Webhelp | All | All | All | All |
| Application | Sync | Oxygen Xml Webhelp | 22.1 | 2020061014 | All | All |
| Application | Sync | Oxygen Xml Webhelp | 22.1 | 2020072412 | All | All |
| Application | Sync | Oxygen Xml Webhelp | 22.1 | 2020100208 | All | All |
| Application | Sync | Oxygen Xml Webhelp | 22.1 | 2020121713 | All | All |
| Application | Sync | Oxygen Xml Webhelp | 23.1 | 2021030210 | All | All |
| Application | Sync | Oxygen Xml Webhelp | 23.1 | 2021040711 | All | All |
| Application | Sync | Oxygen Xml Webhelp | 23.1 | 2021060306 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SYNC-2021-072301 - JavaScript Injection Vulnerability in WebHelp Output | MISC | www.oxygenxml.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.