← back
CVE-2021-21447

CVE-2021-21447

CVSS 5.4 MEDIUMEPSS 0.5%
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
12 Jan 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SAP BusinessObjects Business Intelligence platform, versions 410, 420, allows an authenticated attacker to inject malicious JavaScript payload into the custom value input field of an Input Control, which can be executed by User who views the relevant application content, which leads to Stored Cross-Site Scripting.
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →