CVE-2021-32852
Last modified
CVE-2021-32852 is a critical-severity vulnerability rated 9/10 on the CVSS scale. Countly, a product analytics solution, is vulnerable to cross-site scripting prior to version 21.11 of the community edition. The victim must follow a malicious link or be redirected there from malicious web site. EPSS estimates a 0.93% chance of exploitation in the next 30 days.
Description
Countly, a product analytics solution, is vulnerable to cross-site scripting prior to version 21.11 of the community edition. The victim must follow a malicious link or be redirected there from malicious web site. The attacker must have an account or be able to create one. This issue is patched in version 21.11.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Count | Countly Server | < 21.11 |
References
- https://securitylab.github.com/advisories/GHSL-2021-104-countly-server/Exploit, Third Party Advisory
- https://securitylab.github.com/advisories/GHSL-2021-104-countly-server/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-32852?
How severe is CVE-2021-32852?
How do I fix CVE-2021-32852?
Are you affected by CVE-2021-32852?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
