packetstormsecurity.com
http://packetstormsecurity.com/files/166068/Thinfinity-VirtualUI-2.5.41.0-IFRAME-Injection.html CVE-2021-45092
CRITICALNuclei
Thinfinity VirtualUI before 3.0 lab.html IFRAME Injection
Record summary
CVE-2021-45092 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
thinfinity_virtualuiBrowse cybelesoft / thinfinity_virtualui | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBThinfinity VirtualUI 2.5.41.0 - IFRAME InjectionExploitDB exploitby Daniel MoralesNot analyzed1 file
Nuclei templates
1ProjectDiscoveryCRITICALThinfinity Iframe InjectionCVSS 9.8
A vulnerability exists in Thinfinity VirtualUI in a function located in /lab.html reachable which by default could allow IFRAME injection via the "vpath" parameter.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential remote code execution.
Remediation
Apply the latest security patches or updates provided by the vendor to fix the vulnerability.
WeaknessesCWE-74
Authorsdanielmofer
Template tagscve2021cvepacketstormiframethinfinitytenableinjectioncybelesoftvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:cybelesoft:thinfinity_virtualui:*:*:*:*:*:*:*:*
Shodan: http.title:"thinfinity virtualui"
FOFA: title="thinfinity virtualui"
Google: intitle:"thinfinity virtualui"
https://github.com/cybelesoft/virtualui/issues/2 https://nvd.nist.gov/vuln/detail/CVE-2021-44848 https://www.tenable.com/cve/CVE-2021-45092 http://packetstormsecurity.com/files/166068/Thinfinity-VirtualUI-2.5.41.0-IFRAME-Injection.html https://github.com/danielmofer/nuclei_templates
Source: ProjectDiscovery
References
3github.com
https://github.com/cybelesoft/virtualui/issues/2 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-45092