ZeroHour

CVE-2021-31674

PoC ×2
CVSS 3.1
6.1 medium
EPSS
4%p90
Published
()
Modified
Description

Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant.

Vendors
cyclos
Products
cyclos
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.