CVE-2021-26722: XSS
Published Feb 5, 2021
·Updated
LinkedIn Oncall through 1.4.0 allows reflected XSS via /query because of mishandling of the "No results found for" message in the search bar.
Affected Software
2 affected componentsFixes available
LinkedIn Oncall<=1.4.0
pip/oncall<1.4.1
1.4.1
Event History
Feb 5, 2021
CVE Published
via MITRE·05:12 PM
Data Sourced
via MITRE·05:12 PM
Description
Apr 30, 2021
Advisory Published
via GitHub·05:27 PM
Frequently Asked Questions
1
What is CVE-2021-26722?
CVE-2021-26722 is a vulnerability in LinkedIn Oncall through version 1.4.0 that allows reflected XSS via the /query endpoint.
2
What is the severity of CVE-2021-26722?
The severity of CVE-2021-26722 is medium with a CVSS score of 6.1.
3
How does CVE-2021-26722 occur?
CVE-2021-26722 occurs due to mishandling of the "No results found for" message in the search bar of LinkedIn Oncall.
4
What software versions are affected by CVE-2021-26722?
LinkedIn Oncall versions up to and including 1.4.0 are affected by CVE-2021-26722.
5
Is there a fix for CVE-2021-26722?
A fix for CVE-2021-26722 may be available in a future release of LinkedIn Oncall.