Lucene search

K
cvelistMitreCVELIST:CVE-2021-40970
HistoryOct 01, 2021 - 3:42 p.m.

CVE-2021-40970

2021-10-0115:42:11
mitre
www.cve.org
1
cve-2021-40970
cross-site scripting
spotweb 1.5.1
remote attackers
web script
html
username parameter

EPSS

0.001

Percentile

50.0%

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the username parameter.

EPSS

0.001

Percentile

50.0%

Related for CVELIST:CVE-2021-40970