ZeroHour

CVE-2021-30174

CVSS 3.1
5.4 medium
EPSS
<1%p46
Published
()
Modified
Description

RiyaLab CloudISO event item is added, special characters in specific field of time management page are not properly filtered, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks.

Vendors
ruiyanai
Products
cloudiso
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.