CVE-2021-41172

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
26/10/2021
Last modified:
27/10/2021

Description

AS_Redis is an AntSword plugin for Redis. The Redis Manage plugin for AntSword prior to version 0.5 is vulnerable to Self-XSS due to due to insufficient input validation and sanitization via redis server configuration. Self-XSS in the plugin configuration leads to code execution. This issue is patched in version 0.5.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:antsword_redis_project:antsword_redis:*:*:*:*:*:antsword:*:* 0.5 (excluding)