Medium severity6.1NVD Advisory· Published Feb 21, 2023· Updated Jun 17, 2026
CVE-2021-32859
CVE-2021-32859
Description
The Baremetrics date range picker is a solution for selecting both date ranges and single dates from a single calender view. Versions 1.0.14 and prior are prone to cross-site scripting (XSS) when handling untrusted placeholder entries. An attacker who is able to influence the field placeholder when creating a Calendar instance is able to supply arbitrary html or javascript that will be rendered in the context of a user leading to XSS. There are no known patches for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
baremetrics-calendarnpm | <= 1.0.14 | — |
Affected products
3- Baremetrics/baremetrics-calendarv5Range: 1.0.14
Patches
Vulnerability mechanics
References
5- github.com/Baremetrics/calendar/blob/240c20134ffbf0f0f246a50feff2be1ff19cf349/public/js/Calendar.jsnvdPatchThird Party AdvisoryWEB
- securitylab.github.com/advisories/GHSL-2021-1042_Baremetrics_Date_Range_Picker/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-465f-mxxh-grc4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-32859ghsaADVISORY
- securitylab.github.com/advisories/GHSL-2021-1042_Baremetrics_Date_Range_PickerghsaADVISORY
News mentions
0No linked articles in our index yet.