ZeroHour

CVE-2021-38560

CVSS 3.1
6.1 medium
EPSS
3%p86
Published
()
Modified
Description

Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx.

Vendors
ivanti
Products
service manager
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.