CVE-2021-33850

MEDIUM

Microsoft Clarity 0.3 - Stored Cross-Site Scripting in Project Configuration

Title source: llm
STIX 2.1

Description

There is a Cross-Site Scripting vulnerability in Microsoft Clarity version 0.3. The XSS payload executes whenever the user changes the clarity configuration in Microsoft Clarity version 0.3. The payload is stored on the configuring project Id page.

References (1)

Core 1

Scores

CVSS v3 5.4
EPSS 0.0151
EPSS Percentile 71.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
microsoft/clarity 0.3
Published Nov 19, 2021
Tracked Since Feb 18, 2026