LiveActive security incident?Get immediate response
CVE Record

CVE-2021-36609: Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /linkedcontent/editfolder...

Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /linkedcontent/editfolder.php.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2021-36609 is a reported cross-site scripting issue in webTareas 2.2p1. The Name field in the linked-content folder editor can be abused to inject script content. Business risk depends on whether the affected feature is reachable by untrusted users and whether administrators or other users view the submitted content.

Executive priority

Prioritize this as a targeted application risk rather than a broad emergency. Escalate if webTareas 2.2p1 is internet-facing, accepts input from many users, or is used by privileged staff.

Technical view

The CVE describes XSS in webTareas 2.2p1 through the Name field handled by /linkedcontent/editfolder.php. The public bundle does not provide CVSS, CWE, authentication requirements, exploit prerequisites, or a confirmed fixed version. Treat this as an input handling and output encoding flaw until vendor details clarify scope.

Likely exposure

Exposure is most likely in organizations running webTareas 2.2p1 where linked-content folder editing is available to users. The bundle does not confirm other affected versions, default exposure, or whether authentication is required.

Exploitation context

CISA KEV status is false, and the provided sources do not show active exploitation. The practical impact depends on whether an attacker can set the Name field and whether higher-privileged users later render that content.

Researcher notes

The evidence is sparse: one CVE description and a SourceForge ticket reference. No CVSS, CWE, affected CPE, fixed version, or exploitation evidence is included. Avoid broad version claims without validating against the project source or maintainer guidance.

Mitigation direction

  • Check the webTareas project ticket for patch or upgrade guidance.
  • Limit linked-content folder editing to trusted users only.
  • Review the Name field handling for proper output encoding.
  • Apply vendor-supported updates if a fixed webTareas release is available.
  • Use monitoring to flag suspicious script-like content in folder names.

Validation and detection

  • Inventory webTareas deployments and confirm whether version 2.2p1 is present.
  • Check whether /linkedcontent/editfolder.php is reachable in production.
  • Verify who can edit linked-content folder names.
  • Review application code for Name field encoding before rendering.
  • Confirm remediation against vendor guidance before closing the issue.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-36609 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.