CVE-2021-32821

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/01/2023
Last modified:
10/01/2023

Description

MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Service (ReDoS). An attack requires that an attacker can inject a string into a CSS selector at runtime, which is quite common with e.g. jQuery CSS selectors. No patches are available for this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mootools:mootools:*:*:*:*:*:*:*:* 1.6.0 (including)