Advisory #19
Titleremark42 cross-site scripting via locator.URL
CVE IDCVE-2021-29271
VendorUmputun
Affected productremark42
Affected versions- 1.6.0
Vulnerability typeCWE-79 (Cross-site Scripting)
Descriptionremark42 has a vulnerability that allows cross-site scripting via javascript: URL in locator.URL
StatusFixed in 1.6.1
RecommendationUpdate to 1.6.1 or above