Lucene search

K
cvelistMitreCVELIST:CVE-2021-23836
HistoryJan 15, 2021 - 6:26 a.m.

CVE-2021-23836

2021-01-1506:26:46
mitre
www.cve.org

0.002 Low

EPSS

Percentile

64.9%

An issue was discovered in flatCore before 2.0.0 build 139. A stored XSS vulnerability was identified in the prefs_smtp_psw HTTP request body parameter for the acp interface. An admin user can inject malicious client-side script into the affected parameter without any form of input sanitization. The injected payload will be executed in the browser of a user whenever one visits the affected module page.

0.002 Low

EPSS

Percentile

64.9%

Related for CVELIST:CVE-2021-23836