Wocu Monitoring stored Cross-Site Scripting (XSS)
Vulnerability Description
A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of tinymce editor. In order to exploit this vulnerability, the attackers needs an account with enough privileges to view and edit reports.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-4035
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- David Cámara Galindo
Affected Vendor
A3Sec
View all reports →