CVE-2021-26722 – oncall
Package
Manager: pip
Name: oncall
Vulnerable Version: >=0 <1.4.1
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
EPSS: 0.29912 pctl0.96498
Details
LinkedIn Oncall vulnerable to Cross-Site Scripting LinkedIn Oncall through 1.4.0 allows reflected XSS via /query because of mishandling of the "No results found for" message in the search bar.
Metadata
Created: 2021-04-30T17:27:53Z
Modified: 2024-10-07T21:22:52Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-rfw2-x9f8-2f6m/GHSA-rfw2-x9f8-2f6m.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-rfw2-x9f8-2f6m
Finding: F008
Auto approve: 1