Description
Special characters of ERP POS news page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information.
No analysis available yet.
Remediation
Vendor Solution
Update ERP POS version to 2013.2101
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-17107 | Special characters of ERP POS news page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-4707-9c87e-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-17T01:35:45.061Z
Reserved: 2021-04-06T00:00:00.000Z
Link: CVE-2021-30171
No data.
Status : Modified
Published: 2021-05-07T10:15:08.493
Modified: 2024-11-21T06:03:27.143
Link: CVE-2021-30171
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD