CVE-2021-42838
Grand Vice info Co. webopac7 - Reflected XSS
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.1EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
15 Nov 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Grand Vice info Co. webopac7 book search field parameter does not properly restrict the input of special characters, thus unauthenticated attackers can inject JavaScript syntax remotely, and further perform reflective XSS attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
Grand Vice info Co. · webopac7Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →