Record summary

CVE-2021-40542 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute JavaScript code through the link_url parameter in Ajax_url_encode.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMOpensis-Classic 8.0 - Cross-Site ScriptingCVSS 6.1

Opensis-Classic Version 8.0 is affected by cross-site scripting. An unauthenticated user can inject and execute JavaScript code through the link_url parameter in Ajax_url_encode.php.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement of the affected application.

Remediation

To mitigate this vulnerability, it is recommended to apply the latest security patches or updates provided by the vendor.

WeaknessesCWE-79
Authorsalph4byt3
Template tagscve2021cvexssopensisos4edvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:os4ed:opensis:8.0:*:*:*:*:*:*:*
Shodan: http.title:"openSIS"
Shodan: http.title:"opensis"
FOFA: title="opensis"
Google: intitle:"opensis"

Source: ProjectDiscovery

References

2