.. / CVE-2021-42063

Exploit for SAP Knowledge Warehouse <=7.5.0 - Cross-Site Scripting (CVE-2021-42063)

Description:

SAP Knowledge Warehouse 7.30, 7.31, 7.40, and 7.50 contain a reflected cross-site scripting vulnerability via the usage of one SAP KW component within a web browser.

Nuclei Template

View the template here CVE-2021-42063.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-42063.yaml
Copy

References:

https://packetstormsecurity.com/files/166369/SAP-Knowledge-Warehouse-7.50-7.40-7.31-7.30-Cross-Site-Scripting.html
https://twitter.com/MrTuxracer/status/1505934549217382409
http://packetstormsecurity.com/files/166369/SAP-Knowledge-Warehouse-7.50-7.40-7.31-7.30-Cross-Site-Scripting.html
https://nvd.nist.gov/vuln/detail/CVE-2021-42063
https://seclists.org/fulldisclosure/2022/Mar/32