CVE-2021-28161
In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javasc
In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected.
MEDIUM · CVSS 6.1
EPSS 0.00201
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0