CVE-2021-41318
בינונית 6.1
תיאור (מקור, אנגלית)
In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.
מדדים
- CVSS 3.1
-
6.1 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 6% (אחוזון 100) נכון ל-8/10/2026
- CWE
- CWE-79
מוצרים מושפעים
progress: whatsup gold
קישורים
- https://knowledgebase.progress.com/articles/Knowledge/WhatsUp-Gold-Security-Bu… Vendor Advisory
- https://knowledgebase.progress.com/articles/Knowledge/WhatsUp-Gold-Security-Bu… Vendor Advisory
- http://packetstormsecurity.com/files/164359/WhatsUpGold-21.0.3-Cross-Site-Scri… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/164359/WhatsUpGold-21.0.3-Cross-Site-Scri… ExploitThird Party AdvisoryVDB Entry