← Vulnerability feed

Vulnerability record · CVE-2021-42558 · published 12 January 2022

CVE-2021-42558: Mitre caldera cross-site scripting vulnerability

Mitre · Caldera

An issue was discovered in CALDERA 2.8.1. It contains multiple reflected, stored, and self XSS vulnerabilities that may be exploited by authenticated and unauthenticated attackers.

6.1 CVSS 3.1 Medium EPSS 1.1% · top 37.1% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in CALDERA 2.8.1. It contains multiple reflected, stored, and self XSS vulnerabilities that may be exploited by authenticated and unauthenticated attackers.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-42558 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-42559Mitre caldera command injection vulnerabilityAn issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these c…EPSS 2.0%8.8CVE-2021-42560Mitre caldera xml external entity (xxe) vulnerabilityAn issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG docum…EPSS 2.1%8.8CVE-2021-42561Mitre caldera injection vulnerabilityAn issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. Th…EPSS 20%8.8CVE-2020-19907Mitre caldera os command injection vulnerabilityA command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.EPSS 3.0%8.1CVE-2021-42562Mitre caldera improper privilege management vulnerabilityAn issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users having access to read and modi…EPSS 1.2%6.1CVE-2022-40606Mitre caldera cross-site scripting vulnerabilityMITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-20…EPSS 0.46%6.1CVE-2022-40605Mitre caldera cross-site scripting vulnerabilityMITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-20…EPSS 0.46%5.4CVE-2022-41139Mitre caldera cross-site scripting vulnerabilityMITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary commands on …EPSS 0.57%

Source: NIST National Vulnerability Database (record CVE-2021-42558), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.