Skip to content

Possible XSS injection through DataColumn Grid class

Moderate
eternoendless published GHSA-fhhq-4x46-qx77 Mar 30, 2021

Package

No package listed

Affected versions

> 1.7.7.0

Patched versions

1.7.7.3

Description

Impact

An attacker can inject HTML when the Grid Column Type DataColumn is badly used.

Patches

The problem is fixed in 1.7.7.3

References

Cross-site Scripting (XSS) - Stored (CWE-79)

Severity

Moderate

CVE ID

CVE-2021-21398

Weaknesses

No CWEs