CVE-2021-4325
Last modified
CVE-2021-4325 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A vulnerability, which was classified as problematic, has been found in NHN TOAST UI Chart 4.1.4. This issue affects some unknown processing of the component Legend Handler. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
A vulnerability, which was classified as problematic, has been found in NHN TOAST UI Chart 4.1.4. This issue affects some unknown processing of the component Legend Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 4.2.0 is able to address this issue. The identifier of the patch is 1a3f455d17df379e11b501bb5ba1dd1bcc41d63e. It is recommended to upgrade the affected component. The identifier VDB-221501 was assigned to this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nhncloud | Toast Ui Chart | 4.1.4 |
References
- https://github.com/nhn/tui.chart/pull/604Issue Tracking
- https://github.com/nhn/tui.chart/releases/tag/v4.2.0Release Notes
- https://vuldb.com/?ctiid.221501Permissions Required, Third Party Advisory
- https://vuldb.com/?id.221501Permissions Required, Third Party Advisory
- https://github.com/nhn/tui.chart/pull/604Issue Tracking
- https://github.com/nhn/tui.chart/releases/tag/v4.2.0Release Notes
- https://vuldb.com/?ctiid.221501Permissions Required, Third Party Advisory
- https://vuldb.com/?id.221501Permissions Required, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-4325?
How severe is CVE-2021-4325?
How do I fix CVE-2021-4325?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-43243VP9 Video Extensions Information Disclosure Vulnerability5.5
- CVE-2021-43244Windows Kernel Information Disclosure Vulnerability5.5
- CVE-2021-43245Windows Digital TV Tuner Elevation of Privilege Vulnerabilit…7.8
- CVE-2021-43246Windows Hyper-V Denial of Service Vulnerability5.6
- CVE-2021-43247Windows TCP/IP Driver Elevation of Privilege Vulnerability7.8
- CVE-2021-43248Windows Digital Media Receiver Elevation of Privilege Vulner…7.8
- CVE-2021-43255Microsoft Office Trust Center Spoofing Vulnerability5.5
- CVE-2021-43256Microsoft Excel Remote Code Execution Vulnerability7.8
- CVE-2021-43257Lack of Neutralization of Formula Elements in the CSV API of…7.8
- CVE-2021-43258CartView.php in ChurchInfo 1.3.0 allows attackers to achieve…8.8
- CVE-2021-4326A vulnerability in Imperative framework which allows already…7.8
- CVE-2021-43264In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, adj…3.3
Are you affected by CVE-2021-4325?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
