S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-34370 Scanner

CVE-2021-34370 scanner - Cross-Site Scripting (XSS) vulnerability in Accela Technology The Civic Platform

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-34370
6.1
CVSS

Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are configurable security flags and we are unable to reproduce them with the available information.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Accela Civic Platform is a widely utilized software solution designed to streamline government services through automation, digitization, and citizen engagement. This platform offers an extensive suite of capabilities that help modernize government services and better serve citizens by enabling enhanced communication, information sharing, and productivity improvement. It is designed to be flexible enough to meet the unique requirements of a wide variety of government entities, such as cities, counties, states, and federal agencies.

A recent vulnerability detected in the Civic Platform software is CVE-2021-34370. This vulnerability is related to an XSS (cross-site scripting) flaw in the logoutAction.do function of the ssoAdapter component that is present in the software. This vulnerability enables an attacker to inject malicious code into the successURL parameter of the logout page to execute arbitrary JavaScript code in the context of the currently logged-in user who logs out. This can lead to a range of malicious actions, including the theft of sensitive information, financial losses, and other damage to the user's assets.

When exploited, this vulnerability can lead to serious consequences for users and their assets. Malicious actors can steal the user's session cookies and use them to hijack the user's session, enabling them to execute arbitrary code and access sensitive information. This can also result in the exposure of sensitive credentials, such as usernames and passwords, and other valuable assets, such as financial data and intellectual property information. Additionally, attackers can use this vulnerability to conduct phishing and social engineering attacks, which can ultimately lead to identity theft and fraud.

In conclusion, s4e.io, with its pro features, offers an exceptional range of resources to help organizations stay informed and secure. With regular updates and detailed analysis of vulnerabilities, users can stay ahead of the curve and prevent unauthorized access to sensitive information. It is recommended that all users of the Civic Platform and other software solutions conduct regular vulnerability assessments and take reasonable precautions to protect against such threats. By following these recommendations, users can help ensure the security and confidentiality of valuable assets and sensitive information.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take several precautions, including:

  • Keeping software up to date by applying the latest patches and updates.
  • Limiting access to sensitive information and assets by following the principle of least privilege.
  • Implementing strong authentication mechanisms, such as multi-factor authentication and password policies.
  • Raising awareness about the risks of cyberattacks and promoting a culture of security across the organization.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.