← Back

CVE-2021-30133

nvd nist
Published: Jun 9, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

A cross-site scripting (XSS) vulnerability in CloverDX Server 5.9.0, CloverDX 5.8.1, CloverDX 5.7.0, and earlier allows remote attackers to inject arbitrary web script or HTML via the sessionToken parameter of multiple methods in Simple HTTP API. This is resolved in 5.9.1 and 5.10.

Affected (4)

Products: Cloverdx: Cloverdx
1 product
Cloverdx
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Cloverdx
Up to 5.7.0
From 5.9.0 to 5.9.1
Version 5.8.0
Version 5.8.1

References (4)

Source: cve@mitre.org
Release NotesVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.