CVE-2021-41391: XSS
In Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vulnerable to stored XSS via a name, leading to session hijacking and full account takeover.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-41391?
CVE-2021-41391 is a vulnerability in Ericsson ECM before version 18.0 that allows for session hijacking and full account takeover through a stored XSS vulnerability in the Security Management Endpoint in the User Profile Management section.
What is the severity of CVE-2021-41391?
The severity of CVE-2021-41391 is medium, with a CVSS severity score of 5.4.
How does CVE-2021-41391 work?
CVE-2021-41391 works by exploiting a stored XSS vulnerability in the Security Management Endpoint in the User Profile Management section of Ericsson ECM, allowing an attacker to inject malicious code and potentially hijack user sessions and take over accounts.
What software versions are affected by CVE-2021-41391?
The vulnerability affects Ericsson ECM versions before 18.0.
Is there a fix for CVE-2021-41391?
To fix CVE-2021-41391, users should upgrade to version 18.0 or later of Ericsson ECM.