.. / CVE-2021-30151

Exploit for Sidekiq <=6.2.0 - Cross-Site Scripting (CVE-2021-30151)

Description:

Sidekiq through 5.1.3 and 6.x through 6.2.0 contains a cross-site scripting vulnerability via the queue name of the live-poll feature when Internet Explorer is used.

Nuclei Template

View the template here CVE-2021-30151.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-30151.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2021-30151
https://github.com/Elsfa7-110/kenzer-templates
https://lists.debian.org/debian-lts-announce/2023/03/msg00011.html
https://github.com/mperham/sidekiq/issues/4852
https://lists.debian.org/debian-lts-announce/2022/03/msg00015.html