bluedoor data·Trust Centers API·bluedoor.sh

Home / Security updates / UIPS-2021-003 - Security Advisory - UiPath Apps Studio - Persistent Cross-Site Scripting

UIPS-2021-003 - Security Advisory - UiPath Apps Studio - Persistent Cross-Site Scripting

Security updates detail rendered from /security-updates/upd_eaa0e394d93afc6a.

Overview

IDupd_eaa0e394d93afc6a
CollectionSecurity Updates
ProviderSafeBase
CompanyUiPath
URL-
Counts-
Updated-

Raw record

FieldValue
idupd_eaa0e394d93afc6a
providerIdsafebase
organizationIdorg_33d000fdc8a62017
trustCenterIdtc_7d7ee18589030c52
titleUIPS-2021-003 - Security Advisory - UiPath Apps Studio - Persistent Cross-Site Scripting
message**Title: UiPath Apps Studio - Persistent Cross-Site Scripting** Publish Date: Dec 7, 2021 Version: 1.0 General Information Affected Versions: Automation Suite 2021.10.0 Automation Cloud CVSS Score: 7.9 Details: An issue was fixed in the way the uploaded icons are handled. It was possible for a malicious user with the rights to create an App to upload HTML code instead of a valid image. This might allow an attacker to create a malicious URL used to download the image to execute arbitrary JavaScript code. Release Notes: *Links to release notes have been removed as no version is still in support when migrating this advisory to https://trust.uipath.com on November 21, 2025. Links below have been replaced with the latest version of each product affected.* [Latest Version of Automation Suite](https://download.uipath.com/automation-suite/installUiPathAS.sh) Suggested Actions The issue was patched in the latest version available in Automation Cloud and on Automation Suite 2021.10.1. The is
url-
publishedAt2025-11-21
source
{
  "field": "statuspage/public/compliance-update",
  "category": "vulnerabilities"
}
company
{
  "id": "org_33d000fdc8a62017",
  "name": "UiPath",
  "domains": [
    "trust.uipath.com",
    "uipath.com"
  ]
}
trust_center
{
  "id": "tc_7d7ee18589030c52",
  "name": "UiPath",
  "url": "https://trust.uipath.com",
  "host": "trust.uipath.com"
}
provider
{
  "id": "safebase",
  "name": "SafeBase"
}
links
{
  "self": "/v1/security-updates/upd_eaa0e394d93afc6a",
  "company": "/v1/companies/org_33d000fdc8a62017",
  "trust_center": "/v1/trust-centers/tc_7d7ee18589030c52",
  "provider": "/v1/providers/safebase"
}
Get this page with API

Rendered from the bluedoor Trust Centers API. Reproduce it:

GET https://api.bluedoor.sh/trust-centers/v1/security-updates/upd_eaa0e394d93afc6aJSON