S4E just found a high-severity finding from ssl robot vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-45092 Scanner

CVE-2021-45092 scanner - Cross-Site Scripting (XSS) vulnerability in Thinfinity VirtualUI

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-45092
9.8
CVSS

Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Thinfinity VirtualUI is an innovative software solution that enables developers to effortlessly transform their Windows applications into web-based ones. It does this by providing application virtualization, web-enabling and remote desktop services. With Thinfinity VirtualUI, developers can easily create web application interfaces for their legacy Windows applications without having to redesign, re-engineer or rewrite their entire applications.

Recently, a vulnerability was detected in Thinfinity VirtualUI, and it has been given the CVE-2021-45092 code. This vulnerability arises when an attacker is able to inject an IFRAME element via the vpath parameter in the lab.html folder that is reachable by default. As a result, malicious actors can exploit this vulnerability to execute arbitrary script code, steal sensitive data, or even take remote control of a victim's machine.

When this vulnerability is exploited, the consequences can be dire. For businesses, it can lead to a range of problems, such as loss of data, sensitive information leaking out, or business operations being disrupted. End-users can also suffer as their personal information could be stolen or their devices remotely controlled.

It is essential to stay vigilant and up-to-date with the latest digital asset vulnerabilities that could impact your organization or your personal devices. With the pro features of the s4e.io platform, individuals and businesses can easily and quickly learn about the latest threats and vulnerabilities in their digital assets. From vulnerability scanning to threat intelligence, the platform is fully equipped to deliver comprehensive security solutions. Stay safe and secure your digital assets today!

 

REFERENCES

Solution Advice

To mitigate this vulnerability, several precautions can be taken. These include:

  • Disabling the lab.html folder completely by removing it from the Thinfinity VirtualUI server.
  • Running Thinfinity VirtualUI behind a firewall with only trusted sources allowed to access it.
  • Reviewing web server logs regularly to detect any anomalous behaviour.
  • Configuring web server security settings to enforce parameter validation and sanitization.
  • Updating to the latest version of Thinfinity VirtualUI.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.