S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-42551 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in AlCoda NetBiblio WebOPAC affects v. prior to 4.0.0.320.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-42551
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Cross-site Scripting (XSS) vulnerability in the search functionality of AlCoda NetBiblio WebOPAC allows an unauthenticated user to craft a reflected Cross-Site Scripting attack. This issue affects: AlCoda NetBiblio WebOPAC versions prior to 4.0.0.320; versions later than 4.0.0.328. This issue does not affect: AlCoda NetBiblio WebOPAC version 4.0.0.335 and later versions.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
NetBiblio WebOPACby AlCoda
AFFECTED< 4.0.0.320SAFE ✓≥ 4.0.0.320
Updated Aug 21, 2026View on NVD →
Detail

AlCoda NetBiblio WebOPAC is a web-based online public access catalog or OPAC, used by libraries, archives, museum institutions, and documentation centers. The software enables these organizations to manage, share, and discover collections of documents, books, audiovisual materials, and other resources online. The system provides information about the availability, location, and circulation of material to patrons, facilitating easier access and use of the organization's collection.

The CVE-2021-42551 vulnerability is a Cross-Site Scripting (XSS) vulnerability found in the search functionality of AlCoda NetBiblio WebOPAC. The vulnerability occurs when an unauthenticated user crafts a reflected XSS attack. This vulnerability affects WebOPAC versions earlier than 4.0.0.320 and any versions after 4.0.0.328. While the latest version 4.0.0.335 and above are not affected by this vulnerability.

When this vulnerability is exploited, it could lead to unauthorized access to sensitive information by an attacker. The attacker could also potentially hijack user sessions and perform actions such as manipulating search queries, redirecting users to malicious URLs, injecting malware, or stealing personal user data. Additionally, this could lead to violations of privacy laws, affecting the reputation of the organization and causing financial loss or legal implications.

In conclusion, with the pro features of the s4e.io platform, readers of this article can quickly and easily learn about vulnerabilities in their digital assets. The platform provides valuable insights and tools to address security issues and protect against potential attacks for organizations that use AlCoda NetBiblio WebOPAC or any other software. It is essential to take adequate measures to secure digital assets, and organizations should be proactive in identifying and mitigating any potential vulnerabilities and threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, organizations can take a few simple precautions. These include:

  • Ensure that the WebOPAC is updated to the latest version (4.0.0.335 or later).
  • Implement strict access controls that limit user access to sensitive information.
  • Conduct regular penetration testing and vulnerability scanning to identify and mitigate any potential vulnerabilities in WebOPAC and other digital assets.
  • Educate users on how to recognize and report any suspicious activity or phishing attempts.
  • Configure the web server to enable Content Security Policy (CSP) headers that can restrict the execution of malicious scripts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-42551 scanner - Cross-Site Scripting (XSS) vulnerability in AlCoda NetBiblio WebOPAC S4E