CVE-2021-41719
Last modified
CVE-2021-41719 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application 16.1 application till version 16.1 communicates using the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history, referrers, web logs, and other sources.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application 16.1 application till version 16.1 communicates using the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history, referrers, web logs, and other sources.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2021-41719?
How severe is CVE-2021-41719?
How do I fix CVE-2021-41719?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-41697A reflected Cross Site Scripting (XSS) vulnerability exists …6.1
- CVE-2021-4170calibre-web is vulnerable to Improper Neutralization of Inpu…5.4
- CVE-2021-4171calibre-web is vulnerable to Business Logic Errors9.8
- CVE-2021-41714In Tipask < 3.5.9, path parameters entered by the user are n…6.5
- CVE-2021-41715libsixel 1.10.0 is vulnerable to Use after free in libsixel/…8.8
- CVE-2021-41716Maharashtra State Electricity Board Mahavitara Android Appli…9.8
- CVE-2021-4172Cross-site Scripting (XSS) - Stored in GitHub repository sta…5.4
- CVE-2021-41720Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-41728Cross Site Scripting (XSS) vulnerability exists in Sourcecod…6.1
- CVE-2021-41729BaiCloud-cms v2.5.7 is affected by an arbitrary file deletio…9.1
- CVE-2021-4173vim is vulnerable to Use After Free7.8
- CVE-2021-41731Cross Site Scripting (XSS vulnerability exists in )Sourcecod…4.8
Are you affected by CVE-2021-41719?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
