CVE-2021-26678: XSS
A remote unauthenticated stored cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface of ClearPass could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the context of the affected interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26678?
CVE-2021-26678 is a high severity vulnerability due to its ability to allow remote unauthenticated stored cross-site scripting attacks.
How do I fix CVE-2021-26678?
To fix CVE-2021-26678, update Aruba ClearPass Policy Manager to version 6.9.5 or later, or to versions 6.8.8-HF1 or 6.7.14-HF1.
Who is affected by CVE-2021-26678?
CVE-2021-26678 affects users of Aruba ClearPass Policy Manager versions prior to 6.9.5, 6.8.8-HF1, and 6.7.14-HF1.
What does CVE-2021-26678 exploit?
CVE-2021-26678 exploits a vulnerability in the web-based management interface of Aruba ClearPass that enables stored cross-site scripting.
Can CVE-2021-26678 be exploited remotely?
Yes, CVE-2021-26678 can be exploited by unauthenticated remote attackers.