Description
Easytest bulletin board management function of online learning platform does not filter special characters. After obtaining a user’s privilege, remote attackers can inject JavaScript and execute stored XSS attack.
No analysis available yet.
Remediation
Vendor Solution
Update Easytest to version 2100
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-29309 | Easytest bulletin board management function of online learning platform does not filter special characters. After obtaining a user’s privilege, remote attackers can inject JavaScript and execute stored XSS attack. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-5206-3cd3f-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T19:05:14.166Z
Reserved: 2021-10-12T00:00:00.000Z
Link: CVE-2021-42335
No data.
Status : Modified
Published: 2021-10-15T12:15:07.947
Modified: 2024-11-21T06:27:37.833
Link: CVE-2021-42335
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD