ZeroHour

CVE-2021-32536

CVSS 3.1
6.1 medium
EPSS
<1%p54
Published
()
Modified
Description

The login page in the MCUsystem does not filter with special characters, which allows remote attackers can inject JavaScript without privilege and thus perform reflected XSS attacks.

Vendors
mcusystem
Products
mcusystem
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.