A vulnerability has been identified in Polarion ALM (All versions < V21 R2 P2), Polarion WebClient for SVN (All versions). A cross-site scripting is present due to improper neutralization of data sent to the web page through the SVN WebClient in the affected product. An attacker could exploit this to execute arbitrary code and extract sensitive information by sending a specially crafted link to users with administrator privileges.
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: siemens
Published: 2022-03-08T11:31:24
Updated: 2024-08-04T04:25:16.856Z
Reserved: 2021-12-01T00:00:00
Link: CVE-2021-44478
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Modified
Published: 2022-03-08T12:15:11.337
Modified: 2024-11-21T06:31:02.857
Link: CVE-2021-44478
 Redhat
                        Redhat
                    No data.