Description
RiyaLab CloudISO event item is added, special characters in specific field of time management page are not properly filtered, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks.
No analysis available yet.
Remediation
Vendor Solution
Update CloudISO to version 2021.2e
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-17110 | RiyaLab CloudISO event item is added, special characters in specific field of time management page are not properly filtered, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-4718-f16df-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T20:22:31.132Z
Reserved: 2021-04-06T00:00:00.000Z
Link: CVE-2021-30174
No data.
Status : Modified
Published: 2021-05-11T06:15:06.860
Modified: 2024-11-21T06:03:27.520
Link: CVE-2021-30174
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD