CVE-2021-30119
⚪ Do wiadomości
Refleksyjne XSS w HelpDeskTab/rcResults.asp pozwala na wykonanie skryptów przez uwierzytelnionych użytkowników.
CVSS
5.4
EPSS
52.7%
Exploit
poc
Vendor
kaseya
Opis źródłowy (NVD)
Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Example request: `https://x.x.x.x/HelpDeskTab/rcResults.asp?result=<script>alert(document.cookie)</script>` The same is true for the parameter FileName of /done.asp Eaxmple request: `https://x.x.x.x/done.asp?FileName=";</script><script>alert(1);a="&PathData=&originalName=shell.aspx&FileSize=4388&TimeElapsed=00:00:00.078`
exploit xss
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.4 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 52.7% |
| Opublikowano (NVD) | 2021-07-09 14:15:07 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-14 05:16:54 UTC |
Referencje
- https://csirt.divd.nl/2021/07/07/Kaseya-Limited-Disclosure/ (cve@mitre.org) [Patch, Third Party Advisory]
- https://csirt.divd.nl/CVE-2021-30119 (cve@mitre.org) [Exploit, Third Party Advisory]
- https://csirt.divd.nl/DIVD-2021-00011 (cve@mitre.org) [Patch, Third Party Advisory]