Vulnerabilities > CVE-2021-41172 - Unspecified vulnerability in Antsword Redis Project Antsword Redis

047910
CVSS 5.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
antsword-redis-project

Summary

AS_Redis is an AntSword plugin for Redis. The Redis Manage plugin for AntSword prior to version 0.5 is vulnerable to Self-XSS due to due to insufficient input validation and sanitization via redis server configuration. Self-XSS in the plugin configuration leads to code execution. This issue is patched in version 0.5.

Vulnerable Configurations

Part Description Count
Application
Antsword_Redis_Project
1