CVE-2021-31330
Last modified
CVE-2021-31330 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authenticated attacker may inject malicious Javascript code when using Markdown editing within the application which remains persistent.. EPSS estimates a 0.77% chance of exploitation in the next 30 days.
Description
A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authenticated attacker may inject malicious Javascript code when using Markdown editing within the application which remains persistent.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Reviewboard | Review Board | 3.0.20 | — |
| Reviewboard | Review Board | 4.0 | Beta1 |
References
- https://mattschmidt.net/2021/04/14/review-board-xss-discovered/Exploit, Third Party Advisory
- https://www.reviewboard.org/docs/releasenotes/reviewboard/3.0.21/Release Notes, Vendor Advisory
- https://www.reviewboard.org/docs/releasenotes/reviewboard/4.0-rc-2/Release Notes, Vendor Advisory
- https://www.reviewboard.org/news/2021/04/14/review-board-3-0-21-and-4-0-rc-2-security-bug-fixes-and-docker/Release Notes, Vendor Advisory
- https://mattschmidt.net/2021/04/14/review-board-xss-discovered/Exploit, Third Party Advisory
- https://www.reviewboard.org/docs/releasenotes/reviewboard/3.0.21/Release Notes, Vendor Advisory
- https://www.reviewboard.org/docs/releasenotes/reviewboard/4.0-rc-2/Release Notes, Vendor Advisory
- https://www.reviewboard.org/news/2021/04/14/review-board-3-0-21-and-4-0-rc-2-security-bug-fixes-and-docker/Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-31330?
How severe is CVE-2021-31330?
How do I fix CVE-2021-31330?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-31323Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Teleg…5.5
- CVE-2021-31324The unprivileged user portal part of CentOS Web Panel is aff…9.8
- CVE-2021-31326D-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers …9.8
- CVE-2021-31327Stored XSS in Remote Clinic v2.0 in /medicines due to Medici…5.4
- CVE-2021-31329Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Ch…5.4
- CVE-2021-3133The Elementor Contact Form DB plugin before 1.6 for WordPres…6.5
- CVE-2021-31337The Telnet service of the SIMATIC HMI Comfort Panels system …9.8
- CVE-2021-31338A vulnerability has been identified in SINEMA Remote Connect…7.8
- CVE-2021-31339A vulnerability has been identified in Mendix Excel Importer…4.3
- CVE-2021-3134Mubu 2.2.1 allows local users to gain privileges to execute …7.8
- CVE-2021-31340A vulnerability has been identified in SIMATIC RF166C (All v…7.5
- CVE-2021-31341Uploading a table mapping using a manipulated XML file resul…4.3
Are you affected by CVE-2021-31330?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
