{"id":"CVE-2021-41318","title":"In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input","summary":"In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"progress","product":"whatsup_gold","affected":["whatsup_gold < 21.1.0"],"patched":["whatsup_gold 21.1.0"],"published":"2021-09-28","updated":"2026-09-25","sourceUpdated":"2026-09-25T16:48:10.767","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-41318","references":[{"url":"http://packetstormsecurity.com/files/164359/WhatsUpGold-21.0.3-Cross-Site-Scripting.html","label":"cve@mitre.org"},{"url":"https://knowledgebase.progress.com/articles/Knowledge/WhatsUp-Gold-Security-Bulletin-September-2021","label":"cve@mitre.org"},{"url":"http://packetstormsecurity.com/files/164359/WhatsUpGold-21.0.3-Cross-Site-Scripting.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://knowledgebase.progress.com/articles/Knowledge/WhatsUp-Gold-Security-Bulletin-September-2021","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.05881,"epssPercentile":0.92947,"exploits":{"exploitdb":true,"checkedAt":"2026-09-25T17:13:48.609Z"},"exploitAvailable":true,"ingestedAt":"2026-09-25T17:13:13.992Z","slug":"CVE-2021-41318","body":"## Overview\n\nIn Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.\n\n## Affected\n\n- `whatsup_gold < 21.1.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `whatsup_gold 21.1.0`","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":33.6,"likelihood":1.2,"exploitation":12,"ransomware":0},"changes":[]}