Vulnerability CVE-2021-31673


Published: 2022-05-02

Description:
A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to inject arbitrary web script or HTML via the groupId parameter.

See advisories in our WLB2 database:
Topic
Author
Date
Low
Cyclos 4.14.7 groupId DOM Based Cross-Site Scripting (XSS)
Tin Pham
17.05.2022

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://tf1t.gitbook.io/mycve/cylos/cyclos-4.14.7-dom-based-cross-site-scripting-cve-2021-31673
http://cyclos.com

Copyright 2022, cxsecurity.com

 

Back to Top