ZeroHour

CVE-2021-26710

PoC
CVSS 3.1
6.1 medium
EPSS
8%p94
Published
()
Modified
Description

A cross-site scripting (XSS) issue in the login panel in Redwood Report2Web 4.3.4.5 and 4.5.3 allows remote attackers to inject JavaScript via the signIn.do urll parameter.

Vendors
redwood
Products
report2web
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.