CVE-2021-45422
reprisesoftware reprise_license_manager Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2021-45422 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_process "count" parameter via GET. No authentication is required.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 5, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
reprise_license_managerBrowse reprisesoftware / reprise_license_manager | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMReprise License Manager 14.2 - Cross-Site ScriptingCVSS 6.1
Reprise License Manager 14.2 contains a cross-site scripting vulnerability in the /goform/activate_process "count" parameter via GET.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to potential session hijacking, defacement, or theft of sensitive information.
Remediation
Apply the latest security patches or updates provided by the vendor to fix the XSS vulnerability in Reprise License Manager 14.2.
Source: ProjectDiscovery