5.4
CVSSv3

CVE-2021-46888

Published: 21/05/2023 Updated: 26/05/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

An issue exists in hledger prior to 1.23. A Stored Cross-Site Scripting (XSS) vulnerability exists in toBloodhoundJson that allows an malicious user to execute JavaScript by encoding user-controlled values in a payload with base64 and parsing them with the atob function.

Vulnerable Product Search on Vulmon Subscribe to Product

hledger hledger