ZeroHour

CVE-2021-42120

CVSS 3.1
6.5 medium
EPSS
1%p63
Published
()
Modified
Description

Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on all object attributes allows an authenticated remote attacker with Object Modification privileges to insert arbitrarily long strings, eventually leading to exhaustion of the underlying resource.

Vendors
businessdnasolutions
Products
topease
Weakness
CWE-20, CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.