CVE-2021-29272
EUVD-2021-092527.03.2021, 18:15
bluemonday before 1.0.5 allows XSS because certain Go lowercasing converts an uppercase Cyrillic character, defeating a protection mechanism against the "script" string.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| microco | bluemonday | 𝑥 < 1.0.5 |
𝑥
= Vulnerable software versions
Ubuntu Releases