CVE-2021-42856: Reflected Cross-site Scripting at DsaDataTest
It was discovered that the /DsaDataTest endpoint is susceptible to Cross-site scripting (XSS) attack. It was noted that the Metric parameter does not have any input checks on the user input that allows an attacker to craft its own malicious payload to trigger a XSS vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-42856?
CVE-2021-42856 is a vulnerability that allows an attacker to perform a Cross-site scripting (XSS) attack through the /DsaDataTest endpoint.
What is the severity of CVE-2021-42856?
The severity of CVE-2021-42856 is medium (6.1).
Which software is affected by CVE-2021-42856?
Riverbed Steelcentral Appinternals Dynamic Sampling Agent versions 10.0.0 to 12.13.0 are affected by CVE-2021-42856.
How can an attacker exploit CVE-2021-42856?
An attacker can exploit CVE-2021-42856 by crafting a malicious payload in the Metric parameter of the /DsaDataTest endpoint to trigger a Cross-site scripting (XSS) vulnerability.
Is there a fix available for CVE-2021-42856?
There is currently no known fix for CVE-2021-42856. It is recommended to follow the vendor's security advisories and apply any patches or updates as they become available.