Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2021-3010

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Opentext OpenText Portal是加拿大OpenText(Opentext)公司的一套企业门户系统。该系统为企业提供内容聚合和内容管理功能。 OpenText Content Server Version 20.3 存在跨站脚本漏洞,该漏洞允许远程攻击者通过制造恶意的表单值引入任意JavaScript,这些表单值以后不会被清除。

AI Predicted 6.1 Difficulty: Moderate EPSS 0.86% · P55
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-3010

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
There are multiple persistent cross-site scripting (XSS) vulnerabilities in the web interface of OpenText Content Server Version 20.3. The application allows a remote attacker to introduce arbitrary JavaScript by crafting malicious form values that are later not sanitized.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
OpenText 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Opentext OpenText Portal是加拿大OpenText(Opentext)公司的一套企业门户系统。该系统为企业提供内容聚合和内容管理功能。 OpenText Content Server Version 20.3 存在跨站脚本漏洞,该漏洞允许远程攻击者通过制造恶意的表单值引入任意JavaScript,这些表单值以后不会被清除。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2021-3010

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-3010

登录查看更多情报信息。

Exploits & Public PoCs for CVE-2021-3010 (1)

Other References for CVE-2021-3010 (1)

Same Patch Batch · n/a · 2021-02-26 · 24 CVEs total

CVE-2019-11684 9.9 CRITICAL Improper Access Control in Bosch Video Recording Manager
CVE-2021-23345 5.3 MEDIUM Server-side Request Forgery (SSRF)
CVE-2021-0406 MediaTek cameraisp 缓冲区错误漏洞
CVE-2020-27618 GNU C Library 安全漏洞
CVE-2021-21724 ZTE ZXR E all versions up to VRBP 安全漏洞
CVE-2020-24455 tpm2-tss 安全漏洞
CVE-2020-26200 Kaspersky 安全漏洞
CVE-2021-26904 LMA-ISIDA Retriever SQL注入漏洞
CVE-2021-26903 LMA ISIDA Retriever 跨站脚本漏洞
CVE-2021-22661 ProSoft Technology ICX-HWC-A 安全漏洞
CVE-2020-28646 ownCloud 代码问题漏洞
CVE-2020-28199 Amazon Pay Plugin 信息泄露漏洞
CVE-2021-27198 Visualware MyConnection Server 代码问题漏洞
CVE-2021-0405 MediaTek performance driver 缓冲区错误漏洞
CVE-2021-0404 MediaTek mobile_log_d 输入验证错误漏洞
CVE-2021-0403 MediaTek netdiag 信息泄露漏洞
CVE-2021-0402 MediaTek jpeg 缓冲区错误漏洞
CVE-2021-0401 MediaTek vow 竞争条件问题漏洞
CVE-2021-0367 Google Android 竞争条件问题漏洞
CVE-2021-0366 Google Android 竞争条件问题漏洞

Showing top 20 of 24 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2021-3010

No comments yet


Leave a comment