CVE-2021-40959

A

reflected cross-site scripting vulnerability in MONITORAPP Application Insight Web Application Firewall (AIWAF) <= 4.1.6 and <=5.0 was identified on the subpage `/process_management/process_status.xhr.php`. This vulnerability allows an attacker to inject malicious scripts that execute in the context of the victim's session.

References
Configurations

No configuration.

History

25 Dec 2024, 03:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79
Summary
  • (es) Se identificó una vulnerabilidad de cross site scripting reflejado en MONITORAPP Application Insight Web Application Firewall (AIWAF) &lt;= 4.1.6 y &lt;= 5.0 en la subpágina `/process_management/process_status.xhr.php`. Esta vulnerabilidad permite a un atacante inyectar secuencias de comandos maliciosas que se ejecutan en el contexto de la sesión de la víctima.

20 Dec 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-20 22:15

Updated : 2024-12-25 03:15


NVD link : CVE-2021-40959

Mitre link : CVE-2021-40959

CVE.ORG link : CVE-2021-40959


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')