.. / CVE-2021-26710

Exploit for Redwood Report2Web 4.3.4.5 & 4.5.3 - Cross-Site Scripting (CVE-2021-26710)

Description:

Redwood Report2Web 4.3.4.5 and 4.5.3 contains a cross-site scripting vulnerability in the login panel which allows remote attackers to inject JavaScript via the signIn.do urll parameter.

Nuclei Template

View the template here CVE-2021-26710.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-26710.yaml
Copy

References:

https://github.com/ARPSyndicate/cvemon
https://vict0ni.me/redwood-report2web-xss-and-frame-injection/
https://nvd.nist.gov/vuln/detail/CVE-2021-26710
https://vict0ni.me/report2web-xss-frame-injection.html
https://github.com/ARPSyndicate/kenzer-templates