PT-2021-3436 · Unknown · Acs Commons

Christopher Whipp

·

Published

2021-02-02

·

Updated

2021-12-10

·

CVE-2021-21043

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ACS Commons versions 4.9.2 and earlier
Description The issue is related to a Reflected Cross-site Scripting (XSS) vulnerability in version-compare and page-compare due to invalid JCR characters that are not handled correctly. An attacker could potentially exploit this vulnerability to inject malicious JavaScript content into vulnerable form fields and execute it within the context of the victim's browser. Exploitation of this issue requires user interaction in order to be successful.
Recommendations For ACS Commons versions 4.9.2 and earlier, update to version 4.10.0 to resolve the issue. As a temporary workaround, consider restricting access to the version-compare and page-compare features until the update is applied. Avoid using vulnerable form fields in these features until the issue is resolved.

Fix

Memory Corruption

Use After Free

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03288
CVE-2021-21043
GHSA-7R83-W6R8-FH6W
GHSA-F92J-QF46-P6VM

Affected Products

Acs Commons