PublicCVE

CVE-2021-35240

MEDIUM6.5JSON exportCreate alert

Description

A security researcher stored XSS via a Help Server setting. This affects customers using Internet Explorer, because they do not support 'rel=noopener'.

CVSS breakdown

CVSS 3.1
Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
Low

Affected products