ZeroHour

CVE-2021-37470

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p46
Published
()
Modified
Description

In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user can add or modify the affected field to inject arbitrary JavaScript.

Vendors
nchsoftware
Products
webdictate
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.