Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote authenticated attackers to introduce arbitrary JavaScript via the Sensor Description, Email (from/to/cc), System Name, and System Location fields.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-06-30T11:46:22

Updated: 2024-08-04T00:47:42.577Z

Reserved: 2021-06-29T00:00:00

Link: CVE-2021-35956

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-06-30T12:15:07.683

Modified: 2021-07-06T13:20:33.377

Link: CVE-2021-35956

cve-icon Redhat

No data.