CVE-2021-3014: XSS
Published Jan 4, 2021
·Updated
In MikroTik RouterOS through 2021-01-04, the hotspot login page is vulnerable to reflected XSS via the target parameter.
Affected Software
1 affected component
Mikrotik RouterOS<=2021-01-04
Event History
Jan 4, 2021
CVE Published
via MITRE·06:38 PM
Data Sourced
via MITRE·06:38 PM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-3014?
CVE-2021-3014 is a vulnerability in MikroTik RouterOS that allows for reflected XSS via the target parameter on the hotspot login page.
2
How severe is CVE-2021-3014?
CVE-2021-3014 has a severity rating of 6.1, which is considered medium.
3
What is the affected software?
The affected software is MikroTik RouterOS versions up to and including 2021-01-04.
4
How can I fix CVE-2021-3014?
To fix CVE-2021-3014, it is recommended to update to a version of MikroTik RouterOS that is after 2021-01-04.
5
What is the CWE for CVE-2021-3014?
The CWE for CVE-2021-3014 is CWE-79, which is Cross-Site Scripting (XSS).