A cross-site scripting (XSS) issue in the login panel in Redwood Report2Web 4.3.4.5 and 4.5.3 allows remote attackers to inject JavaScript via the signIn.do urll parameter.
References
Link | Resource |
---|---|
https://vict0ni.me/redwood-report2web-xss-and-frame-injection/ | Exploit Third Party Advisory |
https://vict0ni.me/report2web-xss-frame-injection.html | Broken Link |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2021-02-05T07:54:17
Updated: 2022-01-31T15:01:23
Reserved: 2021-02-05T00:00:00
Link: CVE-2021-26710
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-02-05T14:15:18.840
Modified: 2022-02-04T16:17:47.947
Link: CVE-2021-26710
JSON object: View
Redhat Information
No data.
CWE