CVE-2021-29271
27.03.2021, 18:15
remark42 before 1.6.1 allows XSS, as demonstrated by "Locator: Locator{URL:" followed by an XSS payload. This is related to backend/app/store/comment.go and backend/app/store/service/service.go.
Vendor | Product | Version |
---|---|---|
remark42 | remark42 | 𝑥 < 1.6.1 |
𝑥
= Vulnerable software versions