---
id: CVE-2021-35451
title: >-
  In Teradici PCoIP Management Console-Enterprise 20.07.0, an unauthenticated
  user can inject arbitrary text into user browser via the Web application.
summary: >-
  In Teradici PCoIP Management Console-Enterprise 20.07.0, an unauthenticated
  user can inject arbitrary text into user browser via the Web application.
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: teradici
product: pcoip_management_console
affected:
  - pcoip_management_console = 20.07.0
published: '2021-07-07'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-35451'
references:
  - url: 'https://gist.github.com/rvismit/578f9f98d79f22d81a5e45dbbc0b4fa4'
    label: cve@mitre.org
  - url: 'http://teradici.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://gist.github.com/rvismit/578f9f98d79f22d81a5e45dbbc0b4fa4'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00722
epssPercentile: 0.52562
ingestedAt: '2026-07-06T17:03:23.543Z'
---

## Overview

In Teradici PCoIP Management Console-Enterprise 20.07.0, an unauthenticated user can inject arbitrary text into user browser via the Web application.

## Affected

- `pcoip_management_console = 20.07.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
