CVE-2021-30650

A reflected cross-site scripting (XSS) vulnerability in the Symantec Layer7 API Management OAuth Toolkit (OTK) allows a remote attacker to craft a malicious URL for the OTK web UI and target OTK users with phishing attacks or other social engineering techniques. A successful attack allows injecting malicious code into the OTK web UI client application.

Date published : 2022-02-18

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/CVE-2021-30650-Layer7-OAuth-Toolkit-OTK-/20170