Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-46872

Опубликовано: 13 янв. 2023
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other products, permits the javascript: URI scheme and thus can lead to XSS in some applications. (Nim versions 1.6.2 and later are fixed; there may be backports of the fix to some earlier versions. NimForum 2.2.0 is fixed.)

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:nim-lang:nim:*:*:*:*:*:*:*:*
Версия до 1.6.2 (исключая)
cpe:2.3:a:nim-lang:nimforum:*:*:*:*:*:nim:*:*
Версия до 2.2.0 (исключая)

EPSS

Процентиль: 75%
0.0087
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 3 лет назад

An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other products, permits the javascript: URI scheme and thus can lead to XSS in some applications. (Nim versions 1.6.2 and later are fixed; there may be backports of the fix to some earlier versions. NimForum 2.2.0 is fixed.)

CVSS3: 6.1
debian
около 3 лет назад

An issue was discovered in Nim before 1.6.2. The RST module of the Nim ...

CVSS3: 6.1
github
около 3 лет назад

An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other products, permits the javascript: URI scheme and thus can lead to XSS in some applications. (Nim versions 1.6.2 and later are fixed; there may be backports of the fix to some earlier versions. NimForum 2.2.0 is fixed.)

EPSS

Процентиль: 75%
0.0087
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79