PT-2021-24169 · Opmantek · Opmantek Open-Audit Community

Published

2021-12-20

·

Updated

2022-02-28

·

CVE-2021-44916

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Opmantek Open-AudIT Community versions 4.2.0 through 4.2.0
Description: The issue allows malicious JavaScript code to be executed in the victim's browser if a bad value is passed to the routine via a URL. This is a Cross Site Scripting (XSS) issue.
Recommendations: For Opmantek Open-AudIT Community version 4.2.0, update to version 4.3.0 to resolve the issue. As a temporary workaround, consider restricting access to URLs that may pass bad values to the routine. Avoid using URLs that may execute malicious JavaScript code in the victim's browser until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-44916

Affected Products

Opmantek Open-Audit Community