Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-31682

Опубликовано: 22 окт. 2021
Источник: nvd
CVSS3: 6.1
CVSS2: 4.3
EPSS Средний

Описание

The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. This issue impacts versions 6.5 and below. This issue works by passing in a basic XSS payload to a vulnerable GET parameter that is reflected in the output without sanitization.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:automatedlogic:webctrl:*:*:*:*:*:*:*:*
Версия до 6.5 (включая)

EPSS

Процентиль: 97%
0.41198
Средний

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

github
больше 3 лет назад

The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. This issue impacts versions 6.5 and below. This issue works by passing in a basic XSS payload to a vulnerable GET parameter that is reflected in the output without sanitization.

EPSS

Процентиль: 97%
0.41198
Средний

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79