Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-31589

Опубликовано: 05 янв. 2022
Источник: nvd
CVSS3: 6.1
CVSS2: 4.3
EPSS Средний

Описание

A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which allows the injection of unauthenticated, specially-crafted web requests without proper sanitization.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:beyondtrust:appliance_base_software:*:*:*:*:*:*:*:*
Версия до 6.0.1 (включая)

EPSS

Процентиль: 96%
0.27167
Средний

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

github
почти 4 года назад

BeyondTrust Secure Remote Access Base Software through 6.0.1 allows an attacker to achieve full admin access to the appliance, by tricking the administrator into creating a new admin account through an XSS/CSRF attack involving a crafted request to the /appliance/users?action=edit endpoint. This cross-site-scripting (XSS) vulnerability occurs when it does not properly sanitize an unauthenticated crafted web request to the server

EPSS

Процентиль: 96%
0.27167
Средний

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79