HIGH🇵🇱 Wersja polska

CVE-2021-42118

CVSS 8.1v3.1pub. 2021-11-30upd. 2024-11-21

Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 via the Structure Component allows an authenticated remote attacker with Object Modification privileges to inject arbitrary HTML and JavaScript code in an object attribute, which is then rendered in the Structure Component, to alter the intended functionality and steal cookies, the latter allowing for account takeover.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
  • Businessdnasolutions Topease

    APP
    Businessdnasolutions
    ≤ 7.1.27
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2021-42115HIGH8.1same product

Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version...

CVE-2021-42119HIGH7.3same product

Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platfo...

CVE-2021-42123HIGH7.3same product

Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Vers...

CVE-2021-42544HIGH7.5same product

Missing Rate Limiting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version...

CVE-2021-42120MEDIUM6.5same product

Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform...