UI Redressing in TopEase
Vulnerability Description
Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authenticated remote attacker with Object Modification privileges to insert arbitrary HTML without code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-42117
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- SIX Group Services AG, Cyber Controls
More from Business-DNA Solutions GmbH
View All →Affected Vendor
Business-DNA Solutions GmbH
View all reports →