A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions...
Vulnerability Description
A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authenticated attacker may inject malicious Javascript code when using Markdown editing within the application which remains persistent.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-31330
Credits & Attribution
No credits recorded in the NVD database.
References
- https://mattschmidt.net/2021/04/14/review-board-xss-discovered/
- https://www.reviewboard.org/news/2021/04/14/review-board-3-0-21-and-4-0-rc-2-security-bug-fixes-and-docker/
- https://www.reviewboard.org/docs/releasenotes/reviewboard/3.0.21/
- https://www.reviewboard.org/docs/releasenotes/reviewboard/4.0-rc-2/
More from reviewboard
View All →Affected Vendor
reviewboard
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.