Security Advisory

CVE-2021-32609

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-10-18 14:30:12
Last updated 2024-08-03 23:25:30
Assigner apache
CVSS score not scored
State PUBLISHED

Description

Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a chart with a malicious title, injecting html (including scripts) into the page.