Total vulnerabilities in the database
Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx.
CVSS v3:
CVSS v2:
CWEs:
OWASP TOP 10: