Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-83617
HistoryOct 08, 2021 - 12:00 a.m.

Spotweb Cross-Site Scripting Vulnerability

2021-10-0800:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
spotweb
cross-site scripting
vulnerability
php-based
client
remote attackers
arbitrary web scripts
html
newpassword2 parameter
spotnet protocol
software security

EPSS

0.001

Percentile

50.0%

Spotweb is a Php-based Soptnet client that follows the Spotnet protocol from the Spotweb team.A cross-site scripting vulnerability exists in Spotweb 1.5.1 and below, which can be exploited by remote attackers to inject arbitrary Web scripts or HTML via the newpassword2 parameter.

EPSS

0.001

Percentile

50.0%