CVE-2021-41318 – WhatsUpGold 21.0.3 - Stored Cross-Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2021-41318
In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser. En Progress WhatsUp Gold versiones anteriores a 21.1.0, un endpoint de la aplicación no saneaba adecuadamente una entrada maliciosa, lo que podía permitir a un atacante no autenticado ejecutar código arbitrario en el navegador de la víctima WhatsUpGold version 21.0.3 suffers from a persistent cross site scripting vulnerability. • https://www.exploit-db.com/exploits/50366 http://packetstormsecurity.com/files/164359/WhatsUpGold-21.0.3-Cross-Site-Scripting.html https://knowledgebase.progress.com/articles/Knowledge/WhatsUp-Gold-Security-Bulletin-September-2021 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •