Security Advisory

CVE-2021-3163

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-04-12 20:35:07
Last updated 2024-08-03 16:45:51
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

A vulnerability in the HTML editor of Slab Quill 4.8.0 allows an attacker to execute arbitrary JavaScript by storing an XSS payload (a crafted onloadstart attribute of an IMG element) in a text field. Note: Researchers have claimed that this issue is not within the product itself, but is intended behavior in a web browser