peter bassill · operator
$ cve CVE-2021-41318 JSON

CVE-2021-41318 EXPLOIT

6.1
MEDIUM · CVSS 3.1 · EPSS 5.9% (pctl 93)

Patch early

A public exploit exists.

Description

In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.

Scoring

CVSS6.1 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS5.88% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2021-09-28
Last modified2026-09-25

Affected (1)

VendorProduct
progresswhatsup gold

Public exploits

SourceTitleDate
exploit-dbWhatsUpGold 21.0.3 - Stored Cross-Site Scripting (XSS)2021-10-01

References

→ the Explorer  ·  watch your stack  ·  NVD