CVE-2021-32009: Missing XSS guards on firmware page
Published Mar 11, 2022
·Updated
Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject javascript in browser session. This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions.
Affected Software
1 affected component
Secomea GateManager<=9.6.621421014
Event History
Mar 11, 2022
CVE Published
via MITRE·05:53 PM
Data Sourced
via MITRE·05:53 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-32009.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in…'.
3
How does the vulnerability manifest?
The vulnerability allows a logged in user to inject JavaScript in the browser session.
4
Which versions of Secomea GateManager are affected?
Secomea GateManager Version 9.6.621421014 and all prior versions are affected.
5
What is the severity of the vulnerability?
The severity of the vulnerability is medium with a CVSS score of 6.1.