{"id":"CVE-2021-44217","aliases":["GHSA-fxmx-pfm2-85m2","PYSEC-2022-43181","PYSEC-2026-625"],"url":"https://o3.security/vulnerability/CVE-2021-44217","summary":"Cross-site Scripting in Ericsson CodeChecker","details":"In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remote attackers to inject arbitrary web script or HTML via the POST JSON data of the /CodeCheckerService API.","published":"2022-01-18T15:15:08.253Z","modified":"2026-07-09T05:14:41.385225Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"codechecker","fixedVersion":"6.18.2"}],"fix":{"url":"https://github.com/Ericsson/codechecker/pull/3549","label":"Ericsson/codechecker#3549"},"references":[{"type":"ADVISORY","url":"https://github.com/Ericsson/codechecker/releases"},{"type":"ADVISORY","url":"https://user-images.githubusercontent.com/9525971/142965091-e118b012-a7fc-4c2f-ad0c-80aeed6f7ec9.png"},{"type":"REPORT","url":"https://codechecker-demo.eastus.cloudapp.azure.com/"},{"type":"FIX","url":"https://github.com/Ericsson/codechecker/pull/3549"},{"type":"EVIDENCE","url":"https://github.com/Hyperkopite/CVE-2021-44217/blob/main/README.md"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T05:14:41.385225Z"}}