ZeroHour

CVE-2021-32539

CVSS 3.1
5.4 medium
EPSS
<1%p46
Published
()
Modified
Description

Add event in calendar function in the 101EIP system does not filter special characters in specific fields, which allows remote authenticated users to inject JavaScript and perform a stored XSS attack.

Vendors
hundredplus
Products
101eip
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.