PT-2022-12039 · Unknown · Firmware Analysis/Comparison Tool

Published

2022-03-30

·

Updated

2022-04-08

·

CVE-2021-44310

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firmware Analysis and Comparison Tool version 3.2
Description The issue allows an attacker with administrator privileges to perform stored XSS attacks by inserting JavaScript and HTML code in the user creation functionality.
Recommendations For Firmware Analysis and Comparison Tool version 3.2, consider disabling the user creation functionality until a patch is available to prevent stored XSS attacks. Restrict access to the user creation module to minimize the risk of exploitation. Avoid using the user creation functionality with administrator privileges until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-44310

Affected Products

Firmware Analysis/Comparison Tool