CVE-2021-44916
MEDIUMOpmantek Open-audit < 4.2.0 - XSS
Title source: ruleDescription
Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed to the routine via a URL, malicious JavaScript code can be executed in the victim's browser.
Exploits (1)
References (4)
Scores
CVSS v3
6.1
EPSS
0.0446
EPSS Percentile
89.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
opmantek/open-audit
< 4.2.0
Published
Dec 20, 2021
Tracked Since
Feb 18, 2026