CVE-2021-30056: XSS
Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in /restful-services/publish via the 'EXECFROM' parameter that can lead to data leakage.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-30056?
CVE-2021-30056 is a vulnerability in Knowage Suite before version 7.4 that allows for reflected cross-site scripting (XSS) attacks.
How does CVE-2021-30056 exploit the vulnerability?
CVE-2021-30056 allows an attacker to inject arbitrary web script in the '/restful-services/publish' endpoint via the 'EXEC_FROM' parameter, which can lead to data leakage.
What is the severity of CVE-2021-30056?
The severity of CVE-2021-30056 is medium, with a CVSS score of 5.4.
How can I fix the CVE-2021-30056 vulnerability?
To fix the CVE-2021-30056 vulnerability, upgrade Knowage Suite to version 7.4 or above.
Where can I find more information about CVE-2021-30056?
More information about CVE-2021-30056 can be found at: https://github.com/piuppi/Proof-of-Concepts/blob/main/Engineering/XSS-KnowageSuite.md