CVE-2021-4035
4.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.7 / Impact: 2.7
Source: NVD
Description
A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of tinymce editor. In order to exploit this vulnerability, the attackers needs an account with enough privileges to view and edit reports.
Affected (1)
Products: Wocu Monitoring: Wocu Monitoring
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 0.27 to 48.2 |
References (2)
Source: cve-coordination@incibe.es
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.