CVE-2021-33850
MEDIUMMicrosoft Clarity 0.3 - Stored Cross-Site Scripting in Project Configuration
Title source: llmDescription
There is a Cross-Site Scripting vulnerability in Microsoft Clarity version 0.3. The XSS payload executes whenever the user changes the clarity configuration in Microsoft Clarity version 0.3. The payload is stored on the configuring project Id page.
References (1)
Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://cybersecurityworks.com/zerodays/cve-2021-33850-stored-cross-site-scripting-xss-in-wordpress-microsoft-clarity-plugin.html
Scores
CVSS v3
5.4
EPSS
0.0151
EPSS Percentile
71.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
microsoft/clarity
0.3
Published
Nov 19, 2021
Tracked Since
Feb 18, 2026