CVE-2021-30133

A cross-site scripting (XSS) vulnerability in CloverDX Server 5.9.0, CloverDX 5.8.1, CloverDX 5.7.0, and earlier allows remote attackers to inject arbitrary web script or HTML via the sessionToken parameter of multiple methods in Simple HTTP API. This is resolved in 5.9.1 and 5.10.
References
Link Resource
https://support1.cloverdx.com/hc/en-us/articles/360021006520 Patch Vendor Advisory
https://support.cloverdx.com/releases/ Release Notes Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cloverdx:cloverdx:*:*:*:*:*:*:*:*
cpe:2.3:a:cloverdx:cloverdx:5.8.0:*:*:*:*:*:*:*
cpe:2.3:a:cloverdx:cloverdx:5.8.1:*:*:*:*:*:*:*
cpe:2.3:a:cloverdx:cloverdx:*:*:*:*:*:*:*:*

Information

Published : 2021-06-09 08:15

Updated : 2021-06-10 13:19


NVD link : CVE-2021-30133

Mitre link : CVE-2021-30133


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

cloverdx

  • cloverdx