Description
Special characters of ERP POS customer profile page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information.
No analysis available yet.
Remediation
Vendor Solution
Update ERP POS version to 2013.2101
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-17106 | Special characters of ERP POS customer profile page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-4707-9c87e-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T23:21:33.023Z
Reserved: 2021-04-06T00:00:00.000Z
Link: CVE-2021-30170
No data.
Status : Modified
Published: 2021-05-07T10:15:08.430
Modified: 2024-11-21T06:03:27.020
Link: CVE-2021-30170
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD