SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-35488

Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title parameter.

MEDIUM 6.1EPSS 2.78%

Does this matter?

Lower severity and a low EPSS score (2.78%). Track it; it rarely justifies an emergency change on its own.

Description

Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title parameter. An attacker could inject arbitrary JavaScript into status.cgi. The payload would be triggered every time an authenticated user browses the page containing it.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
2.78% probability · 86th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
thruk/thruk
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.