CVE-2021-28048
14.04.2021, 20:15
An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows a remote attacker to leak cross-origin data via a crafted HTML page.Enginsight
Vendor | Product | Version |
---|---|---|
devolutions | devolutions_server | 𝑥 < 2020.3.18 |
devolutions | devolutions_server | 𝑥 < 2021.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration