CVE-2021-30057: Medium severity knowage vulnerability
Published Apr 5, 2021
·Updated
A stored HTML injection vulnerability exists in Knowage Suite version 7.1. An attacker can inject arbitrary HTML in "/restful-services/2.0/analyticalDrivers" via the 'LABEL' and 'NAME' parameters.
Affected Software
1 affected component
eng Knowage<7.4
Event History
Apr 5, 2021
CVE Published
via MITRE·10:45 AM
Data Sourced
via MITRE·10:45 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-30057?
CVE-2021-30057 is classified as a medium severity vulnerability.
2
How do I fix CVE-2021-30057?
To fix CVE-2021-30057, upgrade Knowage Suite to version 7.4 or higher.
3
What kind of attacks can be executed using CVE-2021-30057?
An attacker can execute stored HTML injection attacks via the 'LABEL' and 'NAME' parameters.
4
Is CVE-2021-30057 present in all versions of Knowage Suite?
CVE-2021-30057 affects Knowage Suite versions prior to 7.4.
5
What impact does CVE-2021-30057 have on affected systems?
CVE-2021-30057 can lead to unauthorized content being injected into the application, potentially impacting users.