← Back

CVE-2021-40096

nvd nist
Published: Dec 7, 2021Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via modification of the authorisationUrl in some integration configurations.

Affected (3)

Products: Squaredup: Squaredup
1 product
Squaredup
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Squaredup
Before 5.3.1
Before 5.3.1
Before 5.3.1

Timeline

No history available yet.