CVE-2021-23411

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the main functionality. It accepts input that can result in the output (an anchor a tag) containing undesirable Javascript code that can be executed upon user interaction.
Configurations

Configuration 1 (hide)

cpe:2.3:a:anchorme_project:anchorme:*:*:*:*:*:node.js:*:*

History

21 Nov 2024, 05:51

Type Values Removed Values Added
CVSS v2 : 4.3
v3 : 6.1
v2 : 4.3
v3 : 5.4
References () https://github.com/alexcorvi/anchorme.js/blob/gh-pages/src/transform.ts%23L81 - Broken Link () https://github.com/alexcorvi/anchorme.js/blob/gh-pages/src/transform.ts%23L81 - Broken Link
References () https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1320695 - Exploit, Third Party Advisory () https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1320695 - Exploit, Third Party Advisory
References () https://snyk.io/vuln/SNYK-JS-ANCHORME-1311008 - Exploit, Third Party Advisory () https://snyk.io/vuln/SNYK-JS-ANCHORME-1311008 - Exploit, Third Party Advisory

30 Jul 2021, 19:15

Type Values Removed Values Added
Summary All versions of package anchorme are vulnerable to Cross-site Scripting (XSS) via the main functionality. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the main functionality. It accepts input that can result in the output (an anchor a tag) containing undesirable Javascript code that can be executed upon user interaction.

29 Jul 2021, 17:32

Type Values Removed Values Added
CPE cpe:2.3:a:anchorme_project:anchorme:*:*:*:*:*:node.js:*:*
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 6.1
References (MISC) https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1320695 - (MISC) https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1320695 - Exploit, Third Party Advisory
References (MISC) https://snyk.io/vuln/SNYK-JS-ANCHORME-1311008 - (MISC) https://snyk.io/vuln/SNYK-JS-ANCHORME-1311008 - Exploit, Third Party Advisory
References (MISC) https://github.com/alexcorvi/anchorme.js/blob/gh-pages/src/transform.ts%23L81 - (MISC) https://github.com/alexcorvi/anchorme.js/blob/gh-pages/src/transform.ts%23L81 - Broken Link

21 Jul 2021, 15:21

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-21 15:15

Updated : 2024-11-21 05:51


NVD link : CVE-2021-23411

Mitre link : CVE-2021-23411

CVE.ORG link : CVE-2021-23411


JSON object : View

Products Affected

anchorme_project

  • anchorme
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')