CVE-2021-41086

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-41086
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-41086.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-41086
Aliases
Related
Published
2021-09-21T21:15:07.130Z
Modified
2025-11-14T12:21:43.526295Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

jsuites is an open source collection of common required javascript web components. In affected versions users are subject to cross site scripting (XSS) attacks via clipboard content. jsuites is vulnerable to DOM based XSS if the user can be tricked into copying anything from a malicious and pasting it into the html editor. This is because a part of the clipboard content is directly written to innerHTML allowing for javascript injection and thus XSS. Users are advised to update to version 4.9.11 to resolve.

References

Affected packages

Git / github.com/jsuites/jsuites

Affected ranges

Type
GIT
Repo
https://github.com/jsuites/jsuites
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

v3.*

v3.1.0
v3.5.0
v3.7.0
v3.9.9

v4.*

v4.4.2