First published: Fri Feb 05 2021(Updated: )
Opmantek Open-AudIT 4.0.1 is affected by cross-site scripting (XSS). When outputting SQL statements for debugging, a maliciously crafted query can trigger an XSS attack. This attack only succeeds if the user is already logged in to Open-AudIT before they click the malicious link.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opmantek Open-AudIT | =4.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3333 is a vulnerability in Opmantek Open-AudIT 4.0.1 that allows for cross-site scripting (XSS) attacks.
CVE-2021-3333 allows for XSS attacks by using a maliciously crafted query when outputting SQL statements for debugging.
CVE-2021-3333 has a severity rating of 6.1 (medium).
Yes, CVE-2021-3333 can only be exploited if the user is already logged in to Open-AudIT before clicking the malicious link.
To fix CVE-2021-3333, it is recommended to update to a version of Open-AudIT that is not affected by this vulnerability.