Logrhythm Web Console 7.4.9 allows for HTML tag injection through Contextualize Action -> Create a new Contextualize Action -> Inject your HTML tag in the name field.
References
Link | Resource |
---|---|
https://medium.com/@idema16/how-i-found-a-cve-in-logrhythm-cve-2021-41943-61cef1797cb | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-12-12 16:15
Updated : 2022-12-15 10:19
NVD link : CVE-2021-41943
Mitre link : CVE-2021-41943
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
logrhythm
- logrhythm