CVE-2021-26968: XSS
A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the web-based management interface of AirWave could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the context of the affected interface.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this cross-site scripting (XSS) vulnerability in Aruba AirWave Management Platform?
The vulnerability ID is CVE-2021-26968.
What is the severity rating of CVE-2021-26968?
The severity rating of CVE-2021-26968 is 4.8, which is considered medium.
How does this vulnerability affect Aruba AirWave Management Platform?
This vulnerability affects Aruba AirWave Management Platform versions prior to 8.2.12.0.
What is the impact of this vulnerability?
The impact of this vulnerability is that an authenticated remote attacker could conduct a stored cross-site scripting (XSS) attack.
Is there a fix for this vulnerability?
Yes, upgrading to version 8.2.12.0 or later of Aruba AirWave Management Platform will fix this vulnerability.