CVE-2021-31589
beyondtrust appliance_base_software Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2021-31589 has a selected CVSS score of 6.1 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which allows the injection of unauthenticated, specially-crafted web requests without proper sanitization.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
appliance_base_softwareBrowse beyondtrust / appliance_base_software | VulnCheck | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHubkarthi-the-hacker/CVE-2021-31589Repository PoCby karthi-the-hackerStars: 1Not analyzed9 files
Nuclei templates
1ProjectDiscoveryMEDIUMBeyondTrust Secure Remote Access Base <=6.0.1 - Cross-Site ScriptingCVSS 6.1
BeyondTrust Secure Remote Access Base through 6.0.1 contains a cross-site scripting vulnerability which allows remote attackers to inject arbitrary web script or HTML.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, data theft, or defacement.
Remediation
Upgrade to a patched version of BeyondTrust Secure Remote Access Base (6.0.2 or higher) that addresses the XSS vulnerability.
Source: ProjectDiscovery