CVE-2021-30058: XSS
Published Apr 5, 2021
·Updated
Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS). An attacker can inject arbitrary external script in '/knowagecockpitengine/api/1.0/pages/execute' via the 'SBIHOST' parameter.
Affected Software
1 affected component
eng Knowage<7.4
Event History
Apr 5, 2021
CVE Published
via MITRE·10:45 AM
Data Sourced
via MITRE·10:45 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-30058?
CVE-2021-30058 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2021-30058?
To fix CVE-2021-30058, upgrade to Knowage Suite version 7.4 or later to mitigate the cross-site scripting vulnerability.
3
What types of attacks can CVE-2021-30058 facilitate?
CVE-2021-30058 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts.
4
Which versions of Knowage are affected by CVE-2021-30058?
CVE-2021-30058 affects all versions of Knowage Suite prior to version 7.4.
5
What parameter is exploited in CVE-2021-30058?
The 'SBI_HOST' parameter is exploited in CVE-2021-30058 to inject arbitrary external scripts.