Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-46827: 2021-072301 - JavaScript Injection Vulnerability in WebHelp Output

An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS vulnerability in search terms proposals (in online documentation generated using Oxygen XML WebHelp) allows attackers to execute JavaScript by convincing a user to type specific text in the WebHelp output search field.

CVE
#xss#vulnerability#web#java#auth

Severity: Medium2021-08-25

Security Advisories

Abstract

There is a JavaScript injection vulnerability in WebHelp output. Using XSS attack, an attacker may inject Javascript code by typing specific expression in search field. This exploit requires a user to be tricked into executing malicious code, by searching for specific text.

Affected Products/Versions

Product

Severity

Fixed Release Availability

Oxygen XML WebHelp 23.1 and older versions

Medium

Oxygen XML WebHelp 23.1 build 2021090310
Oxygen XML WebHelp 22.1 build 2021082006

Oxygen Publishing Engine 23.1 and older versions

Medium

Oxygen Publishing Engine 23.1 build 2021082101
Oxygen Publishing Engine 22.1 build 2021082009

Oxygen XML Editor 23.1 and older versions

Medium

Oxygen XML Editor 23.1 build 2021082307
Oxygen XML Editor 22.1 build 2021082013

Oxygen XML Developer 23.1 and older versions

Medium

Oxygen XML Developer 23.1 build 2021082307
Oxygen XML Developer 22.1 build 2021082013

Oxygen XML Author 23.1 and older versions

Medium

Oxygen XML Author 23.1 build 2021082307
Oxygen XML Author 22.1 build 2021082013

Mitigation

None

Detail

SYNC-2021-072301

Severity: Medium

CVSS Score: 5.5

Oxygen XML WebHelp output is vulnerable to cross-site scripting. This vulnerability allows users to inject arbitrary JavaScript code in the WebHelp output thus altering the intended functionality.

To fix this vulnerability, you need to:

  1. Update your products to a non-vulnerable version.
  2. Replace the WebHelp outputs that were previously generated using one of the affected products with freshly generated ones.

The vulnerability has been fixed in version 22.1 starting with build 2021082013 and version 23.1 starting with build 2021082307.

Revision History

2022-07-13 CVE-2021-46827 CVE ID has been assigned for this vulnerability.

List of Security Advisories

Related news

CVE-2023-32449: DSA-2023-173: Dell PowerStore Family Security Update for Multiple Vulnerabilities

Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a high privileged user to install a malicious binary by bypassing the existing cryptographic signature checks

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907