PT-2021-23272 · Unknown · Xss Hunter Express

Ryotak

·

Published

2021-09-17

·

Updated

2021-09-28

·

CVE-2021-41317

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XSS Hunter Express versions prior to 2021-09-17
Description The issue is related to the improper enforcement of authentication requirements for certain paths. This could potentially allow unauthorized access to sensitive areas of the application.
Recommendations For versions prior to 2021-09-17, update to a version released after 2021-09-17 to ensure proper authentication enforcement. As a temporary workaround, consider restricting access to sensitive paths until a patch is available.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41317

Affected Products

Xss Hunter Express