CVE-2021-29272
27.03.2021, 18:15
bluemonday before 1.0.5 allows XSS because certain Go lowercasing converts an uppercase Cyrillic character, defeating a protection mechanism against the "script" string.
| Vendor | Product | Version |
|---|---|---|
| microco | bluemonday | 𝑥 < 1.0.5 |
𝑥
= Vulnerable software versions
Ubuntu Releases