CVE-2021-38560: XSS
Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-38560?
CVE-2021-38560 is a vulnerability in Ivanti Service Manager 2021.1 that allows reflected XSS via the appName parameter associated with ConfigDB calls.
What is the severity of CVE-2021-38560?
The severity of CVE-2021-38560 is medium with a severity value of 6.1.
How does CVE-2021-38560 affect Ivanti Service Manager?
CVE-2021-38560 affects Ivanti Service Manager 2021.1.
How can the reflected XSS vulnerability in CVE-2021-38560 be exploited?
The reflected XSS vulnerability in CVE-2021-38560 can be exploited via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx.
Are there any references for CVE-2021-38560?
Yes, references for CVE-2021-38560 can be found at the following URLs: [Reference 1](https://forums.ivanti.com/s/article/Ivanti-Service-Manager-Asset-Manager-2021-1-Release-Notes?language=en_US) and [Reference 2](https://github.com/os909/iVANTI-CVE-2021-38560).