CVE-2021-32542
Last modified
CVE-2021-32542 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. The parameters of the specific functions in the CTS Web trading system do not filter special characters, which allows unauthenticated attackers can remotely perform reflected XSS and obtain the users’ connection token that triggered the attack.. EPSS estimates a 0.68% chance of exploitation in the next 30 days.
Description
The parameters of the specific functions in the CTS Web trading system do not filter special characters, which allows unauthenticated attackers can remotely perform reflected XSS and obtain the users’ connection token that triggered the attack.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sysjust | Cts Web | < 2021.3.24 |
References
- https://www.chtsecurity.com/news/40e165e2-e539-49bc-bcf1-e3b27c29e344Third Party Advisory
- https://www.twcert.org.tw/tw/cp-132-4758-82b05-1.htmlThird Party Advisory
- https://www.chtsecurity.com/news/40e165e2-e539-49bc-bcf1-e3b27c29e344Third Party Advisory
- https://www.twcert.org.tw/tw/cp-132-4758-82b05-1.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-32542?
How severe is CVE-2021-32542?
How do I fix CVE-2021-32542?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-32537Realtek HAD contains a driver crashed vulnerability which al…6.5
- CVE-2021-32538ARTWARE CMS parameter of image upload function does not filt…9.8
- CVE-2021-32539Add event in calendar function in the 101EIP system does not…5.4
- CVE-2021-3254Asus DSL-N14U-B1 1.1.2.3_805 allows remote attackers to caus…7.5
- CVE-2021-32540Add announcement function in the 101EIP system does not filt…5.4
- CVE-2021-32541The CTS Web transaction system related to authentication and…5.3
- CVE-2021-32543The CTS Web transaction system related to authentication man…5.4
- CVE-2021-32544Special characters of IGT search function in igt+ are not fi…5.4
- CVE-2021-32545Pexip Infinity before 26 allows remote denial of service bec…7.5
- CVE-2021-32546Missing input validation in internal/db/repo_editor.go in Go…8.8
- CVE-2021-32547It was discovered that read_file() in apport/hookutils.py wo…5.5
- CVE-2021-32548It was discovered that read_file() in apport/hookutils.py wo…5.5
Are you affected by CVE-2021-32542?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
