Record summary

CVE-2021-40272 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

OP5 Monitor 8.3.1, 8.3.2, and OP5 8.3.3 are vulnerable to Cross Site Scripting (XSS).

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 30, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryMEDIUMIRTS OP5 Monitor - Cross-Site Scripting

OP5 Monitor 8.3.1, 8.3.2, and OP5 8.3.3 are vulnerable to Cross Site Scripting (XSS).

Impact

Successful exploitation could lead to unauthorized access or data theft.

Remediation

Update to the latest version of OP5 Monitor to mitigate the XSS vulnerability.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscve2021cveirtsop5xssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:op5:monitor:*:*:*:*:*:*:*:*
Shodan: title:"ITRS"
FOFA: title="ITRS"

Source: ProjectDiscovery

References

2