S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-30213 Scanner

CVE-2021-30213 scanner - Cross-Site Scripting (XSS) vulnerability in Knowage Suite

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-30213
6.1
CVSS

Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in '/servlet/AdapterHTTP' via the 'targetService' parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Knowage Suite is an open-source business intelligence suite intended to enhance data analysis and visualization for organizations. This product provides features such as data access, advanced statistical analyses and reporting tools to achieve optimal business results. Knowage Suite allows its users to integrate business data from various sources and visualize it through customized reports and analytics.

Recently, a vulnerability has been found in Knowage Suite version 7.3, designated CVE-2021-30213. This vulnerability is an unauthenticated reflected cross-site scripting (XSS) attack that can be injected through the 'targetService' parameter in '/servlet/AdapterHTTP.' An attacker can easily exploit this vulnerability to insert arbitrary web scripts to steal user data and credentials.

When a user clicks on a page hosting the malicious injected script, it will execute within the user's browser. This execution will enable access to the user's session or sensitive information stored in cookies, allowing the attacker to exploit the victim's account. In addition, this vulnerability could be used to launch additional attacks in association with the compromised user’s account.

Thanks to the pro features of the s4e.io platform, readers of this article can quickly and easily gain knowledge of the security vulnerabilities in their digital assets. With s4e.io, it is now possible to protect businesses against unforeseeable risks by staying up to date on potential threats and getting access to expert advice and security tools. Using the platform can ensure businesses maintain secure operations while enhancing confidence and preventing financial loss caused by cyber threats.

 

REFERENCES

Solution Advice

To protect against the vulnerability, it is recommended to apply the following precautions:

  • Install the latest update releases of the product.
  • Apply appropriate web application firewall to protect against an XSS attack.
  • Limit the sending of sensitive data to back-end systems.
  • Use security plug-ins and robust development practices to prevent future risks.
  • Stay informed about emerging vulnerabilities and update the system accordingly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-30213 scanner - Cross-Site Scripting (XSS) vulnerability in Knowage Suite | S4E