CVE-2021-34370
38Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 10.0%
from disclosure to weapon5 days
Published on NVDJun 9
1st PoC+5d
exploitation probability
10.0%top 5% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are configurable security flags and we are unable to reproduce them with the available information.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/49990unverifiedcve_referencepacketstormsecurity.com/files/163115/Accela-Civic-Platform-21.1-Cross-Site-Scripting-Open-Redirection.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.