CVE-2021-31589: XSS
Published Jan 5, 2022
·Updated
A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which allows the injection of unauthenticated, specially-crafted web requests without proper sanitization.
Affected Software
1 affected component
BeyondTrust Appliance Base Software<=6.0.1
Event History
Jan 5, 2022
CVE Published
via MITRE·11:26 AM
Data Sourced
via MITRE·11:26 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this cross-site scripting (XSS) vulnerability?
The vulnerability ID for this cross-site scripting (XSS) vulnerability is CVE-2021-31589.
2
What is the severity of CVE-2021-31589?
The severity of CVE-2021-31589 is medium (6.1).
3
Which software versions are affected by CVE-2021-31589?
BeyondTrust Secure Remote Access Base Software version 6.0.1 and older are affected by CVE-2021-31589.
4
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The Common Weakness Enumeration (CWE) ID for CVE-2021-31589 is CWE-79.
5
How can I fix the cross-site scripting (XSS) vulnerability CVE-2021-31589?
To fix the CVE-2021-31589 vulnerability, it is recommended to update BeyondTrust Secure Remote Access Base Software to a version higher than 6.0.1.