Cross-site scripting in Oxygen XML WebHelp - CVE-2021-46827

 

Cross-site scripting in Oxygen XML WebHelp - CVE-2021-46827

Published: September 2, 2022


Vulnerability identifier: #VU66942
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2021-46827
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data in search terms proposals in online documentation generated with Oxygen XML WebHelp. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

Oxygen XML WebHelp
PowerStore T
Avamar Virtual Edition
Dell OpenManage Enterprise Update Manager
EMC Avamar
Dell OpenManage Enterprise Power Manager Plugin
Dell EMC OpenManage Server Administrator
EMC NetWorker Server
Dell EMC AppSync
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)

How to mitigate CVE-2021-46827

Install update from vendor's website.

Oxygen XML WebHelp - addressed in versions 22.1 2021082006, 23.1 2021090310
Dell OpenManage Enterprise Update Manager - update to 1.3
Dell OpenManage Enterprise Power Manager Plugin - update to 3.0
PowerStore T - update to 3.5.0.1-2083289
Dell EMC AppSync - update to 4.5.0.0
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.2.0.5.004
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.2.0.5.004
Dell EMC Unity Operating Environment (OE) - update to 5.2.2.0.5.004
Dell EMC OpenManage Server Administrator - update to 10.3.0
EMC NetWorker Server - update to 19.7.0.2
EMC Avamar - update to 19.8
Avamar Virtual Edition - update to 19.8

External References

Related Security Bulletins