Reflected Cross-site Scripting at DsaDataTest
Vulnerability Description
It was discovered that the /DsaDataTest endpoint is susceptible to Cross-site scripting (XSS) attack. It was noted that the Metric parameter does not have any input checks on the user input that allows an attacker to craft its own malicious payload to trigger a XSS vulnerability.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-42856
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Darrel Huang, Bjorn Lim, Leng Kang Hao from Government Technology Agency of Singapore
More from Aternity
View All →Affected Vendor
Aternity
View all reports →