CVE-2021-23411

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the main functionality. It accepts input that can result in the output (an anchor a tag) containing undesirable Javascript code that can be executed upon user interaction.
Configurations

Configuration 1 (hide)

cpe:2.3:a:anchorme_project:anchorme:*:*:*:*:*:node.js:*:*

History

21 Nov 2024, 05:51

Type Values Removed Values Added
References () https://github.com/alexcorvi/anchorme.js/blob/gh-pages/src/transform.ts%23L81 - Broken Link () https://github.com/alexcorvi/anchorme.js/blob/gh-pages/src/transform.ts%23L81 - Broken Link
References () https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1320695 - Exploit, Third Party Advisory () https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1320695 - Exploit, Third Party Advisory
References () https://snyk.io/vuln/SNYK-JS-ANCHORME-1311008 - Exploit, Third Party Advisory () https://snyk.io/vuln/SNYK-JS-ANCHORME-1311008 - Exploit, Third Party Advisory
CVSS v2 : 4.3
v3 : 6.1
v2 : 4.3
v3 : 5.4

Information

Published : 2021-07-21 15:15

Updated : 2024-11-21 05:51


NVD link : CVE-2021-23411

Mitre link : CVE-2021-23411

CVE.ORG link : CVE-2021-23411


JSON object : View

Products Affected

anchorme_project

  • anchorme
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')