CVE-2021-44310
Last modified
CVE-2021-44310 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. An issue was discovered in Firmware Analysis and Comparison Tool v3.2. With administrator privileges, the attacker could perform stored XSS attacks by inserting JavaScript and HTML code in user creation functionality.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
An issue was discovered in Firmware Analysis and Comparison Tool v3.2. With administrator privileges, the attacker could perform stored XSS attacks by inserting JavaScript and HTML code in user creation functionality.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Firmware Analysis And Comparison Tool Project | Firmware Analysis And Comparison Tool | 3.2 |
References
- https://brainy-sternum-995.notion.site/CVE-2021-44310-Reserved-e9efc897f9944464b8807d44c6fc21dfExploit, Third Party Advisory
- https://brainy-sternum-995.notion.site/CVE-2021-44310-Reserved-e9efc897f9944464b8807d44c6fc21dfExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-44310?
How severe is CVE-2021-44310?
How do I fix CVE-2021-44310?
Are you affected by CVE-2021-44310?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
