← back
CVE-2021-29676

CVE-2021-29676

CVSS 4.6 MEDIUMEPSS 0.8%
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.6EPSS 0.8%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
25 Jun 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this vulnerability to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking
CVSS:3.0/I:L/AV:N/A:N/PR:L/AC:L/C:L/S:U/UI:R/E:U/RL:O/RC:C