ZeroHour

CVE-2021-41434

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p46
Published
()
Modified
Description

A stored Cross-Site Scripting (XSS) vulnerability exists in version 1.0 of the Expense Management System application that allows for arbitrary execution of JavaScript commands through index.php.

Vendors
oretnom23
Products
expense management system
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.