CVE-2021-42535: VISAM VBASE Editor Cross Site Scripting
Published Jul 27, 2022
·Updated
VISAM VBASE version 11.6.0.6 does not neutralize or incorrectly neutralizes user-controllable input before the data is placed in output used as a public-facing webpage.
Affected Software
2 affected components
VISAM VBASE Pro-RT/ Server-RT (Web Remote)=11.6.0.6
VISAM VBASE Web-Remote=11.6.0.6
Remediation
Information
VISAM recommends users update to VBASE v11.7.0.2 or later. Users may obtain a download link by submitting a request form.
For more information, please contact VISAM using the information provided on the company contact page.
Event History
Jul 27, 2022
CVE Published
via MITRE·08:21 PM
Data Sourced
via MITRE·08:21 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-42535?
CVE-2021-42535 is categorized as a moderate severity vulnerability due to its potential for user-controlled input exploitation.
2
How do I fix CVE-2021-42535?
To fix CVE-2021-42535, ensure that all user-controllable inputs are validated and sanitized before they are used in output rendering.
3
What impact does CVE-2021-42535 have on my system?
CVE-2021-42535 may allow an attacker to execute cross-site scripting (XSS) attacks against users accessing the affected webpage.
4
Which versions of VBASE are affected by CVE-2021-42535?
CVE-2021-42535 specifically affects VISAM VBASE version 11.6.0.6.
5
Is there a patch available for CVE-2021-42535?
As of now, there is no widely published patch for CVE-2021-42535, so organizations should implement input validation measures.