Medium severity5.4NVD Advisory· Published Aug 5, 2021· Updated Jun 17, 2026
CVE-2021-38138
CVE-2021-38138
Description
OneNav beta 0.9.12 allows XSS via the Add Link feature. NOTE: the vendor's position is that there intentionally is not any XSS protection at present, because the attack risk is largely limited to a compromised account; however, XSS protection is planned for a future release.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- OneNav/OneNavdescription
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/163753/OneNav-Beta-0.9.12-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB Entry
- github.com/helloxz/onenav/issues/26nvdExploitThird Party Advisory
- github.com/helloxz/onenav/releasesnvdThird Party Advisory
News mentions
0No linked articles in our index yet.