CVE-2021-30211: XSS
Published May 12, 2021
·Updated
Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/signup/update' via the 'surname' parameter.
Affected Software
1 affected component
eng Knowage=7.3.0
Event History
May 12, 2021
CVE Published
via MITRE·04:12 PM
Data Sourced
via MITRE·04:12 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-30211?
CVE-2021-30211 is categorized as a high severity vulnerability due to its potential for stored cross-site scripting attacks.
2
How do I fix CVE-2021-30211?
To fix CVE-2021-30211, ensure you validate and sanitize input for the 'surname' parameter in the Knowage Suite.
3
What systems are affected by CVE-2021-30211?
CVE-2021-30211 affects Knowage Suite version 7.3.0.
4
Can CVE-2021-30211 be exploited remotely?
Yes, CVE-2021-30211 can be exploited remotely by an attacker injecting scripts through the vulnerable endpoint.
5
What are the potential impacts of CVE-2021-30211?
The potential impacts of CVE-2021-30211 include unauthorized data access, user session hijacking, and defacement of web application content.