CVE-2021-41415: XSS
Published Jun 15, 2022
·Updated
Subscription-Manager v1.0 /main.js has a cross-site scripting (XSS) vulnerability in the machineDetail parameter.
Affected Software
1 affected component
Subscription-manager Project Subscription-manager=1.0
Event History
Jun 15, 2022
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-41415?
CVE-2021-41415 has been rated as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2021-41415?
To fix CVE-2021-41415, update your Subscription-Manager to the latest version that patches the XSS vulnerability.
3
What type of vulnerability is CVE-2021-41415?
CVE-2021-41415 is classified as a cross-site scripting (XSS) vulnerability.
4
Which version of Subscription-Manager is affected by CVE-2021-41415?
CVE-2021-41415 specifically affects Subscription-Manager version 1.0.
5
What is the impact of CVE-2021-41415?
The impact of CVE-2021-41415 allows an attacker to execute arbitrary JavaScript in a user's browser via the machineDetail parameter.