{"api_version":"1","generated_at":"2026-07-23T10:03:32+00:00","cve":"CVE-2021-3271","urls":{"html":"https://cve.report/CVE-2021-3271","api":"https://cve.report/api/cve/CVE-2021-3271.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-3271","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-3271"},"summary":{"title":"CVE-2021-3271","description":"PressBooks 5.17.3 contains a cross-site scripting (XSS). Stored XSS can be submitted via the Book Info's Long Description Body, and all actions to open or preview the books page will result in the triggering the stored XSS.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-02-18 19:15:00","updated_at":"2021-02-24 14:45:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://www.gosecure.net/blog/2021/02/16/cve-2021-3271-pressbooks-stored-cross-site-scripting-proof-of-concept/","name":"https://www.gosecure.net/blog/2021/02/16/cve-2021-3271-pressbooks-stored-cross-site-scripting-proof-of-concept/","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"CVE-2021-3271 Pressbooks Stored Cross Site Scripting Proof of Concept | GoSecure","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/pressbooks/pressbooks/pull/2072","name":"https://github.com/pressbooks/pressbooks/pull/2072","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Fix XSS security vulnerability by arzola · Pull Request #2072 · pressbooks/pressbooks · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/pressbooks/pressbooks","name":"https://github.com/pressbooks/pressbooks","refsource":"MISC","tags":["Third Party Advisory"],"title":"GitHub - pressbooks/pressbooks: Open publishing. Open web. Open source.","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-3271","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3271","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"3271","vulnerable":"1","versionEndIncluding":"5.17.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pressbooks","cpe5":"pressbooks","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-3271","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"PressBooks 5.17.3 contains a cross-site scripting (XSS). Stored XSS can be submitted via the Book Info's Long Description Body, and all actions to open or preview the books page will result in the triggering the stored XSS."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/pressbooks/pressbooks/pull/2072","refsource":"MISC","name":"https://github.com/pressbooks/pressbooks/pull/2072"},{"url":"https://github.com/pressbooks/pressbooks","refsource":"MISC","name":"https://github.com/pressbooks/pressbooks"},{"refsource":"MISC","name":"https://www.gosecure.net/blog/2021/02/16/cve-2021-3271-pressbooks-stored-cross-site-scripting-proof-of-concept/","url":"https://www.gosecure.net/blog/2021/02/16/cve-2021-3271-pressbooks-stored-cross-site-scripting-proof-of-concept/"}]}},"nvd":{"publishedDate":"2021-02-18 19:15:00","lastModifiedDate":"2021-02-24 14:45:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.7,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:pressbooks:pressbooks:*:*:*:*:*:*:*:*","versionEndIncluding":"5.17.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"3271","Ordinal":"200781","Title":"CVE-2021-3271","CVE":"CVE-2021-3271","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"3271","Ordinal":"1","NoteData":"PressBooks 5.17.3 contains a cross-site scripting (XSS). Stored XSS can be submitted via the Book Info's Long Description Body, and all actions to open or preview the books page will result in the triggering the stored XSS.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"3271","Ordinal":"2","NoteData":"2021-01-22","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"3271","Ordinal":"3","NoteData":"2021-02-18","Type":"Other","Title":"Modified"}]}}}