{"api_version":"1","generated_at":"2026-07-23T12:34:20+00:00","cve":"CVE-2021-31330","urls":{"html":"https://cve.report/CVE-2021-31330","api":"https://cve.report/api/cve/CVE-2021-31330.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-31330","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-31330"},"summary":{"title":"CVE-2021-31330","description":"A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authenticated attacker may inject malicious Javascript code when using Markdown editing within the application which remains persistent.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2022-05-11 18:15:00","updated_at":"2022-05-20 14:19:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://mattschmidt.net/2021/04/14/review-board-xss-discovered/","name":"https://mattschmidt.net/2021/04/14/review-board-xss-discovered/","refsource":"MISC","tags":[],"title":"Review Board XSS Discovered – Schmidt Happens – InfoSec Blog","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.reviewboard.org/docs/releasenotes/reviewboard/3.0.21/","name":"https://www.reviewboard.org/docs/releasenotes/reviewboard/3.0.21/","refsource":"MISC","tags":[],"title":"Review Board 3.0.21 Release Notes | Documentation | Review Board","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.reviewboard.org/docs/releasenotes/reviewboard/4.0-rc-2/","name":"https://www.reviewboard.org/docs/releasenotes/reviewboard/4.0-rc-2/","refsource":"MISC","tags":[],"title":"Review Board 4.0 RC 2 Release Notes | Documentation | Review Board","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.reviewboard.org/news/2021/04/14/review-board-3-0-21-and-4-0-rc-2-security-bug-fixes-and-docker/","name":"https://www.reviewboard.org/news/2021/04/14/review-board-3-0-21-and-4-0-rc-2-security-bug-fixes-and-docker/","refsource":"MISC","tags":[],"title":"Review Board 3.0.21 and 4.0 RC 2: Security Fixes, Bug Fixes, and Docker | News | Review Board","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-31330","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-31330","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"31330","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"reviewboard","cpe5":"review_board","cpe6":"3.0.20","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"31330","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"reviewboard","cpe5":"review_board","cpe6":"4.0","cpe7":"beta1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"31330","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"reviewboard","cpe5":"review_board","cpe6":"4.0","cpe7":"beta2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"31330","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"reviewboard","cpe5":"review_board","cpe6":"4.0","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-31330","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authenticated attacker may inject malicious Javascript code when using Markdown editing within the application which remains persistent."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://mattschmidt.net/2021/04/14/review-board-xss-discovered/","refsource":"MISC","name":"https://mattschmidt.net/2021/04/14/review-board-xss-discovered/"},{"url":"https://www.reviewboard.org/news/2021/04/14/review-board-3-0-21-and-4-0-rc-2-security-bug-fixes-and-docker/","refsource":"MISC","name":"https://www.reviewboard.org/news/2021/04/14/review-board-3-0-21-and-4-0-rc-2-security-bug-fixes-and-docker/"},{"url":"https://www.reviewboard.org/docs/releasenotes/reviewboard/3.0.21/","refsource":"MISC","name":"https://www.reviewboard.org/docs/releasenotes/reviewboard/3.0.21/"},{"url":"https://www.reviewboard.org/docs/releasenotes/reviewboard/4.0-rc-2/","refsource":"MISC","name":"https://www.reviewboard.org/docs/releasenotes/reviewboard/4.0-rc-2/"}]}},"nvd":{"publishedDate":"2022-05-11 18:15:00","lastModifiedDate":"2022-05-20 14:19:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:reviewboard:review_board:3.0.20:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:reviewboard:review_board:4.0:beta1:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:reviewboard:review_board:4.0:beta2:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:reviewboard:review_board:4.0:rc1:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"31330","Ordinal":"206614","Title":"CVE-2021-31330","CVE":"CVE-2021-31330","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"31330","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}