PT-2021-19660 · U.S. National Security Agency · Emissary
Dennis Brinkrolf
·
Published
2021-05-07
·
Updated
2021-05-13
·
CVE-2021-32092
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
U.S. National Security Agency (NSA) Emissary version 5.9.0
Description:
A Cross-site scripting (XSS) issue in the DocumentAction component allows remote attackers to inject arbitrary web script or HTML via the
uuid parameter.Recommendations:
For U.S. National Security Agency (NSA) Emissary version 5.9.0, consider restricting access to the DocumentAction component until a fix is available, and avoid using the
uuid parameter in affected API endpoints to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emissary