packetstormsecurity.com
http://packetstormsecurity.com/files/161303/Jenzabar-9.2.2-Cross-Site-Scripting.html CVE-2021-26723
MEDIUMNuclei
Jenzabar 9.2x-9.2.2 - Cross-Site Scripting
Record summary
CVE-2021-26723 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMJenzabar 9.2x-9.2.2 - Cross-Site ScriptingCVSS 6.1
Jenzabar 9.2.x through 9.2.2 contains a cross-site scripting vulnerability. It allows /ics?tool=search&query.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Apply the latest security patch or upgrade to a non-vulnerable version of Jenzabar 9.2x-9.2.2.
WeaknessesCWE-79
Authorspikpikcu
Template tagscve2021cvepacketstormjenzabarxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:jenzabar:jenzabar:*:*:*:*:*:*:*:*
http://packetstormsecurity.com/files/161303/Jenzabar-9.2.2-Cross-Site-Scripting.html https://gist.github.com/Y0ung-DST/d1b6b65be6248b0ffc2b2f2120deb205 https://jenzabar.com/blog https://y0ungdst.medium.com/xss-in-jenzabar-cve-2021-26723-a0749231328 https://nvd.nist.gov/vuln/detail/CVE-2021-26723
Source: ProjectDiscovery
References
5gist.github.com
https://gist.github.com/Y0ung-DST/d1b6b65be6248b0ffc2b2f2120deb205 jenzabar.com
https://jenzabar.com/blog nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-26723 y0ungdst.medium.com
https://y0ungdst.medium.com/xss-in-jenzabar-cve-2021-26723-a0749231328