Record summary

CVE-2021-31589 has a selected CVSS score of 6.1 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which allows the injection of unauthenticated, specially-crafted web requests without proper sanitization.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Aug 19, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubkarthi-the-hacker/CVE-2021-31589Repository PoCby karthi-the-hackerStars: 1Not analyzed9 files

675.0 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMBeyondTrust Secure Remote Access Base <=6.0.1 - Cross-Site ScriptingCVSS 6.1

BeyondTrust Secure Remote Access Base through 6.0.1 contains a cross-site scripting vulnerability which allows remote attackers to inject arbitrary web script or HTML.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, data theft, or defacement.

Remediation

Upgrade to a patched version of BeyondTrust Secure Remote Access Base (6.0.2 or higher) that addresses the XSS vulnerability.

WeaknessesCWE-79
AuthorsAhmed Abou-Ela, r3Y3r53
Template tagscvecve2021xsspacketstormbeyondtrustbomgarvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:o:beyondtrust:appliance_base_software:*:*:*:*:*:*:*:*
Shodan: set-cookie: nsbase_session
Google: "BeyondTrust" "Redistribution Prohibited"
Google: "beyondtrust" "redistribution prohibited"

Source: ProjectDiscovery

References

4