PT-2022-12349 · Reprise · Reprise License Manager

Giulia Melotti Garibaldi

·

Published

2022-01-13

·

Updated

2025-04-30

·

CVE-2021-45422

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Reprise License Manager version 14.2
Description The issue is a reflected cross-site scripting vulnerability in the "/goform/activate process" API endpoint, specifically in the count parameter, which can be exploited via GET requests. No authentication is required to exploit this issue.
Recommendations For Reprise License Manager version 14.2, as a temporary workaround, consider restricting access to the "/goform/activate process" API endpoint or avoiding the use of the count parameter in this endpoint until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-45422

Affected Products

Reprise License Manager