PT-2022-11702 · Insta Hms · Insta Hms
Published
2022-01-06
·
Updated
2022-01-11
·
CVE-2021-42841
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Insta HMS versions prior to 12.4.10
Description
The issue arises from improper validation of user-supplied input by multiple scripts, leading to a potential XSS attack. A remote attacker could exploit this via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site. This could allow the attacker to steal the victim's cookie-based authentication credentials.
Recommendations
For versions prior to 12.4.10, update to version 12.4.10 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially vulnerable scripts to minimize the risk of exploitation. Avoid using crafted URLs that could trigger the execution of malicious scripts in the victim's Web browser.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Insta Hms