PT-2021-24169 · Opmantek · Opmantek Open-Audit Community
Published
2021-12-20
·
Updated
2022-02-28
·
CVE-2021-44916
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Opmantek Open-AudIT Community versions 4.2.0 through 4.2.0
Description:
The issue allows malicious JavaScript code to be executed in the victim's browser if a bad value is passed to the routine via a URL. This is a Cross Site Scripting (XSS) issue.
Recommendations:
For Opmantek Open-AudIT Community version 4.2.0, update to version 4.3.0 to resolve the issue. As a temporary workaround, consider restricting access to URLs that may pass bad values to the routine. Avoid using URLs that may execute malicious JavaScript code in the victim's browser until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opmantek Open-Audit Community