Record summary

CVE-2021-30151 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 5.2.0 · Fixed in 5.2.0affected
6.0.0 to < 6.2.1 · Fixed in 6.2.1affected

Nuclei templates

1
ProjectDiscoveryMEDIUMSidekiq <=6.2.0 - Cross-Site ScriptingCVSS 6.1

Sidekiq through 5.1.3 and 6.x through 6.2.0 contains a cross-site scripting vulnerability via the queue name of the live-poll feature when Internet Explorer is used.

Impact

Successful exploitation of this vulnerability could lead to unauthorized access, data theft, or session hijacking.

Remediation

Upgrade to Sidekiq version 6.2.0 or later to mitigate this vulnerability.

WeaknessesCWE-79
AuthorsDhiyaneshDk
Template tagscve2021cvexsssidekiqauthenticatedcontribsysvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:contribsys:sidekiq:*:*:*:*:*:*:*:*
Shodan: title:"Sidekiq"
Shodan: http.title:"sidekiq"
FOFA: title="sidekiq"
Google: intitle:"sidekiq"

Source: ProjectDiscovery

References

6