{"id":"GHSA-g67g-hvc3-xmvf","summary":"Inconsistent input sanitisation leads to XSS vectors","details":"### Background\n\nA variety of templates do not perform proper sanitization through HTML escaping.\nDue to the lack of sanitization and use of ``jQuery.html()``, there are a whole host of XSS possibilities with specially crafted input to a variety of fields.\n\n### Impact\n\nOMERO.web before 5.11.0 and OMERO.figure before 4.4.1.\n\n### Patches\nUsers should upgrade OMERO.web to 5.11.0 or higher and OMERO.figure to 4.4.1 or higher.","aliases":["CVE-2021-41132","PYSEC-2021-372","PYSEC-2021-379"],"modified":"2026-07-08T06:29:19.719716201Z","published":"2021-10-14T21:19:23Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2021-10-14T18:50:58Z","nvd_published_at":"2021-10-14T16:15:00Z","cwe_ids":["CWE-116","CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/ome/omero-web/security/advisories/GHSA-g67g-hvc3-xmvf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-41132"},{"type":"WEB","url":"https://github.com/ome/omero-web/commit/0168067accde5e635341b3c714b1d53ae92ba424"},{"type":"PACKAGE","url":"https://github.com/ome/omero-web"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/omero-figure/PYSEC-2021-379.yaml"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/omero-web/PYSEC-2021-372.yaml"},{"type":"WEB","url":"https://www.openmicroscopy.org/security/advisories/2021-SV3"}],"affected":[{"package":{"name":"omero-web","ecosystem":"PyPI","purl":"pkg:pypi/omero-web"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.11.0"}]}],"versions":["5.10.0","5.11.0rc1","5.5.dev1","5.5.dev2","5.6.0","5.6.1","5.6.2","5.6.3","5.6.dev1","5.6.dev2","5.6.dev3","5.6.dev4","5.6.dev5","5.6.dev6","5.6.dev7","5.7.0","5.7.1","5.8.0","5.8.1","5.9.0","5.9.1","5.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-g67g-hvc3-xmvf/GHSA-g67g-hvc3-xmvf.json"}},{"package":{"name":"omero-figure","ecosystem":"PyPI","purl":"pkg:pypi/omero-figure"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.4.1"}]}],"versions":["2.0.0","2.0.1","3.0.0","3.1.0","3.1.1","3.1.2","3.2.0","3.2.1","4.0.0","4.0.1","4.0.2","4.1.0","4.2.0","4.2.dev1","4.3.0","4.3.1","4.3.2","4.4.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-g67g-hvc3-xmvf/GHSA-g67g-hvc3-xmvf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}