The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title parameter. After logging in with user’s privilege, remote attackers can inject JavaScript and execute stored XSS attacks.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2021-10-15T12:10:29.738803Z

Updated: 2024-09-17T00:00:29.574Z

Reserved: 2021-10-12T00:00:00

Link: CVE-2021-42329

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-15T12:15:07.570

Modified: 2024-11-21T06:27:37.073

Link: CVE-2021-42329

cve-icon Redhat

No data.