CVE-2021-27930

Multiple stored XSS vulnerabilities in IrisNext Edition 9.5.16, which allows an authenticated (or compromised) user to inject malicious JavaScript in folder/file name within the application in order to grab other users’ sessions or execute malicious code in their browsers (1-click RCE).
Configurations

Configuration 1 (hide)

cpe:2.3:a:irislink:irisnext:9.5.16:*:*:*:*:*:*:*

History

21 Nov 2024, 05:58

Type Values Removed Values Added
References () https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2021-27930.pdf - Exploit, Third Party Advisory () https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2021-27930.pdf - Exploit, Third Party Advisory
References () https://varsnext.iriscorporate.com/history.html - Product () https://varsnext.iriscorporate.com/history.html - Product

09 Jul 2021, 15:37

Type Values Removed Values Added
References (MISC) https://varsnext.iriscorporate.com/history.html - (MISC) https://varsnext.iriscorporate.com/history.html - Product
References (MISC) https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2021-27930.pdf - (MISC) https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2021-27930.pdf - Exploit, Third Party Advisory
CWE CWE-79
CPE cpe:2.3:a:irislink:irisnext:9.5.16:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 3.5
v3 : 5.4

06 Jul 2021, 14:15

Type Values Removed Values Added
Summary Multiple stored cross-site scripting (XSS) vulnerabilities in IRIS IrisNext 9.5.16 allow remote authenticated users to inject arbitrary web script or HTML via a document or folder name that is mishandled when rendering the contact form or search form. Multiple stored XSS vulnerabilities in IrisNext Edition 9.5.16, which allows an authenticated (or compromised) user to inject malicious JavaScript in folder/file name within the application in order to grab other users’ sessions or execute malicious code in their browsers (1-click RCE).

06 Jul 2021, 12:36

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-06 12:15

Updated : 2024-11-21 05:58


NVD link : CVE-2021-27930

Mitre link : CVE-2021-27930

CVE.ORG link : CVE-2021-27930


JSON object : View

Products Affected

irislink

  • irisnext
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')