The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vulnerability could be used to carry out a number of browser-based attacks including browser hijacking or theft of sensitive data.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-33943 | The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vulnerability could be used to carry out a number of browser-based attacks including browser hijacking or theft of sensitive data. |
Fixes
Solution
This vulnerability has been solved by TCMAN in GIM v8.0.1 Release 31734.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-17T03:33:15.052Z
Reserved: 2021-12-02T00:00:00
Link: CVE-2021-4046
No data.
Status : Modified
Published: 2022-02-11T18:15:10.840
Modified: 2024-11-21T06:36:47.530
Link: CVE-2021-4046
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD