6.1
CVSSv3

CVE-2021-44543

Published: 23/12/2021 Updated: 07/11/2023
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

An XSS vulnerability was found in Privoxy which was fixed in cgi_error_no_template() by encode the template name when Privoxy is configured to servce the user-manual itself.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

privoxy privoxy

Vendor Advisories

Several security issues were fixed in Privoxy ...
A security issue has been found in Privoxy before version 3033 cgi_error_no_template() did not encode the template name, which could lead to cross-site scripting when Privoxy is configured to servce the user-manual itself ...

Mailing Lists

Announcing Privoxy 3033 stable -------------------------------------------------------------------- Privoxy 3033 fixes an XSS issue, multiple DoS issues and a couple of other bugs The issues also affect earlier Privoxy releases Privoxy 3033 also comes with a couple of general improvements and new features -------------------------------- ...