mirror of
https://github.com/0xMarcio/cve.git
synced 2026-02-12 18:42:46 +00:00
19 lines
836 B
Markdown
19 lines
836 B
Markdown
### [CVE-2021-40096](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-40096)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via modification of the authorisationUrl in some integration configurations.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://support.squaredup.com
|
|
- https://support.squaredup.com/hc/en-us/articles/4410656396817-CVE-2021-40096-Stored-cross-site-scripting-provider-configuration-
|
|
|
|
#### Github
|
|
- https://github.com/kaje11/CVEs
|
|
|