Description
Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemUsers, login / description fields, passwd1/ passwd2 parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.
No analysis available yet.
Remediation
Vendor Solution
The vulnerability has been fixed by the White Bear Solutions team in version 21.05.00.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-32362 | Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemUsers, login / description fields, passwd1/ passwd2 parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data. |
References
History
Thu, 27 Feb 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Whitebearsolutions
Whitebearsolutions wbsairback |
|
| CPEs | cpe:2.3:a:whitebearsolutions:wbsairback:21.02.04:*:*:*:*:*:*:* | |
| Vendors & Products |
Whitebearsolutions
Whitebearsolutions wbsairback |
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T20:20:01.606Z
Reserved: 2024-04-15T10:18:58.736Z
Link: CVE-2024-3790
Updated: 2024-08-01T20:20:01.606Z
Status : Analyzed
Published: 2024-05-14T15:42:17.243
Modified: 2025-04-10T19:18:12.483
Link: CVE-2024-3790
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD