CVE-2021-30212: XSS
Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/documentnotes/saveNote' via the 'nota' parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-30212?
CVE-2021-30212 refers to a vulnerability in Knowage Suite 7.3, where Stored Cross-Site Scripting (XSS) can occur.
How does CVE-2021-30212 impact Knowage Suite 7.3?
CVE-2021-30212 allows an attacker to inject arbitrary web scripts in the '/knowage/restful-services/documentnotes/saveNote' endpoint via the 'nota' parameter.
What is the severity of CVE-2021-30212?
CVE-2021-30212 has a severity rating of medium.
How can an attacker exploit CVE-2021-30212?
An attacker can exploit CVE-2021-30212 by injecting malicious scripts through the 'nota' parameter in the '/knowage/restful-services/documentnotes/saveNote' endpoint.
Is there a fix available for CVE-2021-30212 in Knowage Suite 7.3?
Currently, there is no known fix for the CVE-2021-30212 vulnerability in Knowage Suite 7.3. It is recommended to follow the provided reference for possible mitigation steps.