PT-2021-23272 · Unknown · Xss Hunter Express
Ryotak
·
Published
2021-09-17
·
Updated
2021-09-28
·
CVE-2021-41317
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
XSS Hunter Express versions prior to 2021-09-17
Description
The issue is related to the improper enforcement of authentication requirements for certain paths. This could potentially allow unauthorized access to sensitive areas of the application.
Recommendations
For versions prior to 2021-09-17, update to a version released after 2021-09-17 to ensure proper authentication enforcement. As a temporary workaround, consider restricting access to sensitive paths until a patch is available.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xss Hunter Express