CVE-2021-3333: XSS
Opmantek Open-AudIT 4.0.1 is affected by cross-site scripting (XSS). When outputting SQL statements for debugging, a maliciously crafted query can trigger an XSS attack. This attack only succeeds if the user is already logged in to Open-AudIT before they click the malicious link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-3333?
CVE-2021-3333 is a vulnerability in Opmantek Open-AudIT 4.0.1 that allows for cross-site scripting (XSS) attacks.
How does CVE-2021-3333 work?
CVE-2021-3333 allows for XSS attacks by using a maliciously crafted query when outputting SQL statements for debugging.
What is the severity of CVE-2021-3333?
CVE-2021-3333 has a severity rating of 6.1 (medium).
Is CVE-2021-3333 only exploitable if the user is logged in?
Yes, CVE-2021-3333 can only be exploited if the user is already logged in to Open-AudIT before clicking the malicious link.
How can I fix CVE-2021-3333?
To fix CVE-2021-3333, it is recommended to update to a version of Open-AudIT that is not affected by this vulnerability.