CVE-2021-40959

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Dec 20, 2024
Updated: Dec 25, 2024
CWE ID 79

Summary

CVE-2021-40959 is a reflected cross-site scripting (XSS) vulnerability affecting MONITORAPP Application Insight Web Application Firewall (AIWAF) versions 4.1.6 and 5.0. The issue was discovered on the `/process_management/process_status.xhr.php` subpage. An attacker can exploit this vulnerability by injecting malicious scripts, which then execute in the context of the victim's session. The successful execution of these scripts could result in unauthorized access or data theft. Users are strongly advised to upgrade their MONITORAPP AIWAF to a patched version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share