The login page in the MCUsystem does not filter with special characters, which allows remote attackers can inject JavaScript without privilege and thus perform reflected XSS attacks.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-19382 | The login page in the MCUsystem does not filter with special characters, which allows remote attackers can inject JavaScript without privilege and thus perform reflected XSS attacks. |
Fixes
Solution
Contact tech support from MCU Technologies.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-4811-4a160-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T22:10:15.250Z
Reserved: 2021-05-10T00:00:00.000Z
Link: CVE-2021-32536
No data.
Status : Modified
Published: 2021-06-18T10:15:09.130
Modified: 2024-11-21T06:07:13.300
Link: CVE-2021-32536
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD