An error in a page handler of the VRM may lead to a reflected cross site scripting (XSS) in the web-based interface. To exploit this vulnerability an attack must be able to modify the HTTP header that is sent. This issue also affects installations of the DIVAR IP and BVMS with VRM installed.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: bosch

Published: 2021-12-08T21:17:28.106105Z

Updated: 2024-09-17T03:52:42.674Z

Reserved: 2021-01-12T00:00:00

Link: CVE-2021-23860

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-12-08T22:15:08.473

Modified: 2021-12-14T16:36:10.037

Link: CVE-2021-23860

cve-icon Redhat

No data.