CVE-2021-34540: XSS
Published Jun 11, 2021
·Updated
Advantech WebAccess 8.4.2 and 8.4.4 allows XSS via the username column of the bwRoot.asp page of WADashboard.
Affected Software
2 affected components
Advantech WebAccess=8.4.2
Advantech WebAccess=8.4.4
Event History
Jun 11, 2021
CVE Published
via MITRE·11:26 AM
Data Sourced
via MITRE·11:26 AM
Description
Frequently Asked Questions
1
What is CVE-2021-34540?
CVE-2021-34540 is a vulnerability in Advantech WebAccess 8.4.2 and 8.4.4 that allows XSS attacks via the username column of the bwRoot.asp page of WADashboard.
2
How severe is CVE-2021-34540?
CVE-2021-34540 has a severity score of 6.1 which is considered medium.
3
How does CVE-2021-34540 affect Advantech WebAccess?
CVE-2021-34540 affects Advantech WebAccess versions 8.4.2 and 8.4.4.
4
How do I fix CVE-2021-34540?
To fix CVE-2021-34540, update Advantech WebAccess to the latest version available.
5
What is CWE-79?
CWE-79 is a common weakness enumeration category for XSS (Cross-Site Scripting) vulnerabilities.