
CVE-2021-42558: Multiple Cross-Site Scripting in MITRE Caldera
Caldera (versions <=2.8.1) contains multiple reflected, stored and self XSS vulnerabilities that may be exploited by authenticated and unauthenticated attackers.
The vendor's disclosure for this vulnerability can be found here.
This vulnerability requires:
More details and the exploitation process can be found in this PDF.
The XSS vector "1.1. Unauthenticated Stored XSS in Agent" was also found in paralel and fixed by Daniel "uruwhy" Matthews in this Caldera commit.