CVE-2021-29252: XSS
Published May 26, 2021
·Updated
RSA Archer before 6.9 SP1 P1 (6.9.1.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user with access to modify link name fields could potentially exploit this vulnerability to execute code in a victim's browser.
Affected Software
4 affected components
RSA Archer>=6.6<6.6.0.8
RSA Archer>=6.7<6.7.0.8
RSA Archer>=6.8<6.8.0.5
RSA Archer>=6.9<6.9.1.1
Event History
May 26, 2021
CVE Published
via MITRE·03:56 AM
Data Sourced
via MITRE·03:56 AM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2021-29252?
CVE-2021-29252 is a stored XSS vulnerability in RSA Archer before 6.9 SP1 P1 (6.9.1.1).
2
How does CVE-2021-29252 affect RSA Archer?
CVE-2021-29252 affects RSA Archer versions 6.6.0.8 to 6.9.1.1.
3
What is the severity of CVE-2021-29252?
The severity of CVE-2021-29252 is medium with a CVSS score of 5.4.
4
How can a remote attacker exploit CVE-2021-29252?
A remote authenticated malicious user with access to modify link name fields in RSA Archer could exploit CVE-2021-29252 to execute code in a victim's browser.
5
Where can I find more information about CVE-2021-29252?
You can find more information about CVE-2021-29252 in the RSA Archer Product Advisories and RSA's vulnerability response policy.