CVE-2021-42558

MEDIUM

Mitre Caldera < 2.8.1 - XSS

Title source: rule
STIX 2.1

Description

An issue was discovered in CALDERA 2.8.1. It contains multiple reflected, stored, and self XSS vulnerabilities that may be exploited by authenticated and unauthenticated attackers.

Exploits (1)

nomisec WRITEUP
by mbadanoiu · poc
https://github.com/mbadanoiu/CVE-2021-42558

References (2)

Core 2
Core References
Release Notes x_refsource_misc
https://github.com/mitre/caldera/releases

Scores

CVSS v3 6.1
EPSS 0.0215
EPSS Percentile 84.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
mitre/caldera < 2.8.1
Published Jan 12, 2022
Tracked Since Feb 18, 2026