CVE-2021-42856
It was discovered that the /DsaDataTest endpoint is susceptible to Cross-site scripting (XSS) attack. It was noted that the Metric parameter does not have any input checks on the user input that allows an attacker to craft its own malicious payload to trigger a XSS vulnerability.
Published:Mar 9, 2022
Last Modified:Nov 21, 2024
EPS:Mar 9, 2022
EPSS Score:0.00202
CVSS Score:4.7
Affected Products
Vendor
Product
Action
Vendor
Riverbed
Product
Steelcentral Appinternals Dynamic Sampling Agent
Riverbed
Steelcentral Appinternals Dynamic Sampling Agent
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
