CVE-2021-46827
An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS vulnerability in search terms proposals (in online documentation generated using Oxygen XML WebHelp) allows attackers to execute JavaScript by convincing a user to type specific text in the WebHelp output search field.
Published:Jul 13, 2022
Last Modified:Nov 21, 2024
EPS:Jul 13, 2022
EPSS Score:0.00638
CVSS Score:6.1
Affected Products
Vendor
Product
Action
Vendor
Sync
Product
Oxygen Publishing Engine
Sync
Oxygen Publishing Engine
Vendor
Sync
Product
Oxygen Xml Author
Sync
Oxygen Xml Author
Vendor
Sync
Product
Oxygen Xml Developer
Sync
Oxygen Xml Developer
Vendor
Sync
Product
Oxygen Xml Editor
Sync
Oxygen Xml Editor
Vendor
Sync
Product
Oxygen Xml Webhelp
Sync
Oxygen Xml Webhelp
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
