Lucene search

K
cveMitreCVE-2021-43657
HistoryDec 22, 2022 - 2:15 a.m.

CVE-2021-43657

2022-12-2202:15:08
CWE-79
mitre
web.nvd.nist.gov
40
cve-2021-43657
stored xss
scms
master.php
vulnerability
security
remote attack

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

29.5%

A Stored Cross-site scripting (XSS) vulnerability via MAster.php in Sourcecodetester Simple Client Management System (SCMS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the vulnerable input fields.

Affected configurations

Nvd
Node
simple_client_management_system_projectsimple_client_management_systemMatch1.0
VendorProductVersionCPE
simple_client_management_system_projectsimple_client_management_system1.0cpe:2.3:a:simple_client_management_system_project:simple_client_management_system:1.0:*:*:*:*:*:*:*

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

29.5%

Related for CVE-2021-43657