packetstormsecurity.com
http://packetstormsecurity.com/files/164359/WhatsUpGold-21.0.3-Cross-Site-Scripting.html CVE-2021-41318
MEDIUM
WhatsUpGold 21.0.3 - Stored Cross-Site Scripting (XSS)
Record summary
CVE-2021-41318 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWhatsUpGold 21.0.3 - Stored Cross-Site Scripting (XSS)ExploitDB exploitby Andreas FinstadNot analyzed1 file
References
3knowledgebase.progress.com
https://knowledgebase.progress.com/articles/Knowledge/WhatsUp-Gold-Security-Bulletin-September-2021 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-41318