In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user can add or modify the affected field to inject arbitrary JavaScript.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-07-25T20:08:15
Updated: 2024-08-04T01:16:04.168Z
Reserved: 2021-07-25T00:00:00
Link: CVE-2021-37470
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-07-25T21:15:08.563
Modified: 2024-11-21T06:15:14.470
Link: CVE-2021-37470
Redhat
No data.