6.1
CVSSv3

CVE-2021-38560

Published: 01/02/2022 Updated: 05/02/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ivanti service manager 2021.1

Github Repositories

iVANTI-CVE-2021-38560 Ivanti Service Manager 20211 infected with reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachmentsaspx Vulnerability Type: Cross Site Scripting (XSS) Vendor of Product: IVANTI Affected Product Versions: Service Manager - (=<20213) Payload: localhost/HEAT/maintenance/RelocateAttachmentsas