CVE-2021-29995 describes a Cross-Site Request Forgery (CSRF) vulnerability in CloverDX Server Console versions up to 5.9.0. This flaw allows remote attackers to perform any action as a logged-in user, including script execution, by tricking them into clicking a malicious link. With a CVSS score of 8.8 (HIGH), the vulnerability has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog and lacking significant community discussion or media coverage, a public exploit (EDB-50166) exists, indicating its potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.7.1CPE matchmatch criteria | cpe:2.3:a:cloverdx:cloverdx:*:*:*:*:*:*:*:* | ||
>= 5.8.0, < 5.8.2CPE matchmatch criteria | cpe:2.3:a:cloverdx:cloverdx:*:*:*:*:*:*:*:* | ||
>= 5.9.0, < 5.9.1CPE matchmatch criteria | cpe:2.3:a:cloverdx:cloverdx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.