A frame-injection issue in the online help in Redwood Report2Web 4.3.4.5 allows remote attackers to render an external resource inside a frame via the help/Online_Help/NetHelp/default.htm turl parameter.
References
Link | Resource |
---|---|
https://vict0ni.me/redwood-report2web-xss-and-frame-injection/ | Exploit Third Party Advisory |
https://vict0ni.me/report2web-xss-frame-injection.html | Broken Link |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2021-02-05T07:53:58
Updated: 2022-01-31T14:46:52
Reserved: 2021-02-05T00:00:00
Link: CVE-2021-26711
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-02-05T14:15:18.903
Modified: 2022-02-04T16:27:37.947
Link: CVE-2021-26711
JSON object: View
Redhat Information
No data.
CWE