Логотип exploitDog
bind:CVE-2021-31930
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-31930

Количество 2

Количество 2

nvd логотип

CVE-2021-31930

больше 4 лет назад

Persistent cross-site scripting (XSS) in the web interface of Concerto through 2.3.6 allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into the First Name or Last Name parameter upon registration. When a privileged user attempts to delete the account, the XSS payload will be executed.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-6x7c-5jc6-7qc6

больше 3 лет назад

Persistent cross-site scripting (XSS) in the web interface of Concerto through 2.3.6 allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into the First Name or Last Name parameter upon registration. When a privileged user attempts to delete the account, the XSS payload will be executed.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-31930

Persistent cross-site scripting (XSS) in the web interface of Concerto through 2.3.6 allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into the First Name or Last Name parameter upon registration. When a privileged user attempts to delete the account, the XSS payload will be executed.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-6x7c-5jc6-7qc6

Persistent cross-site scripting (XSS) in the web interface of Concerto through 2.3.6 allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into the First Name or Last Name parameter upon registration. When a privileged user attempts to delete the account, the XSS payload will be executed.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу