CVE-2021-46827

An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS vulnerability in search terms proposals (in online documentation generated using Oxygen XML WebHelp) allows attackers to execute JavaScript by convincing a user to type specific text in the WebHelp output search field.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
VendorProductVersion
syncoxygen_publishing_engine
𝑥
< 22.1
syncoxygen_publishing_engine
22.1:2020061014
syncoxygen_publishing_engine
22.1:2020072823
syncoxygen_publishing_engine
22.1:2020100801
syncoxygen_publishing_engine
22.1:2020121711
syncoxygen_publishing_engine
23.1:2021040717
syncoxygen_publishing_engine
23.1:2021060401
syncoxygen_xml_author
𝑥
< 22.1
syncoxygen_xml_author
22.1:2020061102
syncoxygen_xml_author
22.1:2020072902
syncoxygen_xml_author
22.1:2020100710
syncoxygen_xml_author
22.1:2020121713
syncoxygen_xml_author
23.1:2021030206
syncoxygen_xml_author
23.1:2021040908
syncoxygen_xml_author
23.1:2021061407
syncoxygen_xml_developer
𝑥
< 22.1
syncoxygen_xml_developer
22.1:2020061102
syncoxygen_xml_developer
22.1:2020072902
syncoxygen_xml_developer
22.1:2020100710
syncoxygen_xml_developer
22.1:2020121713
syncoxygen_xml_developer
23.1:2021030206
syncoxygen_xml_developer
23.1:2021040908
syncoxygen_xml_developer
23.1:2021061407
syncoxygen_xml_editor
𝑥
< 22.1
syncoxygen_xml_editor
22.1:2020061102
syncoxygen_xml_editor
22.1:2020072902
syncoxygen_xml_editor
22.1:2020100710
syncoxygen_xml_editor
22.1:2020121713
syncoxygen_xml_editor
23.1:2021030206
syncoxygen_xml_editor
23.1:2021040908
syncoxygen_xml_editor
23.1:2021061407
syncoxygen_xml_webhelp
𝑥
< 22.1
syncoxygen_xml_webhelp
22.1:2020061014
syncoxygen_xml_webhelp
22.1:2020072412
syncoxygen_xml_webhelp
22.1:2020100208
syncoxygen_xml_webhelp
22.1:2020121713
syncoxygen_xml_webhelp
23.1:2021030210
syncoxygen_xml_webhelp
23.1:2021040711
syncoxygen_xml_webhelp
23.1:2021060306
𝑥
= Vulnerable software versions