312
VMScore

CVE-2021-35475

Published: 25/06/2021 Updated: 01/07/2021
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when editing the Configuration Properties.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sas environment manager 2.5

Exploits

SAS Environment Manager version 25 suffers from a persistent cross site scripting vulnerability ...

Github Repositories

Writeup for CVE-2021-35475; Stored Cross-Site Scripting(XSS) on SAS® Environment Manager 2.5

CVE-2021-35475 Writeup for CVE-2021-35475 Stored Cross-Site Scripting(XSS) on SAS® Environment Manager 25 Writeup will be migrating here