PT-2021-23420 · Verint · Verint Workforce Optimization

Published

2021-10-08

·

Updated

2022-05-03

·

CVE-2021-41825

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Verint Workforce Optimization (WFO) version 15.2.5.1033
Description The issue allows HTML injection via the "/wfo/control/signin" API endpoint, specifically through the username parameter.
Recommendations For version 15.2.5.1033, consider restricting access to the "/wfo/control/signin" API endpoint or validating and sanitizing the username parameter to prevent HTML injection until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41825

Affected Products

Verint Workforce Optimization