Record summary

CVE-2021-45092 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBThinfinity VirtualUI 2.5.41.0 - IFRAME InjectionExploitDB exploitby Daniel MoralesNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALThinfinity Iframe InjectionCVSS 9.8

A vulnerability exists in Thinfinity VirtualUI in a function located in /lab.html reachable which by default could allow IFRAME injection via the "vpath" parameter.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential remote code execution.

Remediation

Apply the latest security patches or updates provided by the vendor to fix the vulnerability.

WeaknessesCWE-74
Authorsdanielmofer
Template tagscve2021cvepacketstormiframethinfinitytenableinjectioncybelesoftvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:cybelesoft:thinfinity_virtualui:*:*:*:*:*:*:*:*
Shodan: http.title:"thinfinity virtualui"
FOFA: title="thinfinity virtualui"
Google: intitle:"thinfinity virtualui"

Source: ProjectDiscovery

References

3