Critical severityNVD Advisory· Published Oct 14, 2021· Updated Aug 4, 2024
Inconsistent input sanitisation leads to XSS vectors
CVE-2021-41132
Description
OMERO.web provides a web based client and plugin infrastructure. In versions prior to 5.11.0, a variety of templates do not perform proper sanitization through HTML escaping. Due to the lack of sanitization and use of `jQuery.html()`, there are a whole host of cross-site scripting possibilities with specially crafted input to a variety of fields. This issue is patched in version 5.11.0. There are no known workarounds aside from upgrading.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
omero-webPyPI | < 5.11.0 | 5.11.0 |
omero-figurePyPI | < 4.4.1 | 4.4.1 |
Affected products
3- ghsa-coords2 versions
< 4.4.1+ 1 more
- (no CPE)range: < 4.4.1
- (no CPE)range: < 5.11.0
Patches
Vulnerability mechanics
Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
8- github.com/advisories/GHSA-g67g-hvc3-xmvfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-41132ghsaADVISORY
- github.com/ome/omero-web/commit/0168067accde5e635341b3c714b1d53ae92ba424ghsax_refsource_MISCWEB
- github.com/ome/omero-web/security/advisories/GHSA-g67g-hvc3-xmvfghsax_refsource_CONFIRMWEB
- github.com/pypa/advisory-database/tree/main/vulns/omero-figure/PYSEC-2021-379.yamlghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/omero-web/PYSEC-2021-372.yamlghsaWEB
- www.openmicroscopy.org/security/advisories/2021-SV3ghsaWEB
- www.openmicroscopy.org/security/advisories/2021-SV3/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.