PT-2022-10220 · Easyvista · Easyvista Service Manager

Armysick

·

Published

2022-10-20

·

Updated

2022-10-22

·

CVE-2021-33231

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions EasyVista Service Manager version 2018.1.181.1
Description The issue is related to a Cross Site Scripting (XSS) vulnerability in the New equipment page. This vulnerability allows remote attackers to run arbitrary code via the notes field.
Recommendations For EasyVista Service Manager version 2018.1.181.1, consider restricting access to the New equipment page or disabling the notes field until a fix is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-33231

Affected Products

Easyvista Service Manager