Lucene search

K
cvelistMitreCVELIST:CVE-2021-40968
HistoryOct 01, 2021 - 3:42 p.m.

CVE-2021-40968

2021-10-0115:42:10
mitre
www.cve.org
2
cross-site scripting
spotweb
installer
remote attackers
web script
html
newpassword2 parameter .

EPSS

0.001

Percentile

50.0%

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the newpassword2 parameter.

EPSS

0.001

Percentile

50.0%

Related for CVELIST:CVE-2021-40968