Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemConfiguration, name / free memory limit fields , type / password parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.
Metrics
Affected Vendors & Products
Fixes
Solution
The vulnerability has been fixed by the White Bear Solutions team in version 21.05.00.
Workaround
No workaround given by the vendor.
References
History
Thu, 27 Feb 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Whitebearsolutions
Whitebearsolutions wbsairback |
|
CPEs | cpe:2.3:a:whitebearsolutions:wbsairback:21.02.04:*:*:*:*:*:*:* | |
Vendors & Products |
Whitebearsolutions
Whitebearsolutions wbsairback |

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T20:20:02.176Z
Reserved: 2024-04-15T10:18:59.440Z
Link: CVE-2024-3791

Updated: 2024-08-01T20:20:02.176Z

Status : Analyzed
Published: 2024-05-14T15:42:17.880
Modified: 2025-04-10T19:27:02.710
Link: CVE-2024-3791

No data.

No data.