An issue was discovered in the Growth extension in MediaWiki through 1.36.2. Any admin can add arbitrary JavaScript code to the Newcomer home page footer, which can be executed by viewers with zero edits.
CWE-79
CVE-2021-42050
An issue was discovered in AbanteCart before 1.3.2. It allows DOM Based XSS.
CVE-2021-42051
An issue was discovered in AbanteCart before 1.3.2. Any low-privileged user with file-upload permissions can upload a malicious SVG document that contains an XSS payload.
CVE-2021-42053
The Unicorn framework through 0.35.3 for Django allows XSS via component.name.
CVE-2021-42061
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) – version 420, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This allows a low privileged attacker to retrieve some data from the victim but will never be able to modify the document and publish these modifications to the server. It impacts the “Quick Prompt” workflow.
CVE-2021-42063
A security vulnerability has been discovered in the SAP Knowledge Warehouse – versions 7.30, 7.31, 7.40, 7.50. The usage of one SAP KW component within a Web browser enables unauthorized attackers to conduct XSS attacks, which might lead to disclose sensitive data.
