Lucene search

K
osvGoogleOSV:CVE-2021-44217
HistoryJan 18, 2022 - 3:15 p.m.

CVE-2021-44217

2022-01-1815:15:08
Google
osv.dev
16
ericsson
codechecker
xss
vulnerability
remote attackers
web script
html
json data
api

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

52.5%

In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remote attackers to inject arbitrary web script or HTML via the POST JSON data of the /CodeCheckerService API.

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

52.5%