9.8
CVSSv3

CVE-2021-45092

Published: 16/12/2021 Updated: 12/07/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Thinfinity VirtualUI prior to 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cybelesoft thinfinity virtualui

Exploits

Thinfinity VirtualUI version 25410 suffers from an iframe injection vulnerability ...

Github Repositories

nuclei_templates

Nuclei Template I have finally decided to contribute to the IT Security field, and what a better way to do it than starting by creating templates for Nuclei (nucleiprojectdiscoveryio) Templates CVE-2021-44848: Thinfinity VirtualUI is a web remote desktop system, a vulnerability exist in the parameter "username" located in /changePassword that allows user enumerati