Lucene search

K
cvelistTwcertCVELIST:CVE-2021-42329
HistoryOct 15, 2021 - 12:00 a.m.

CVE-2021-42329 ShinHer Information Co., LTD. ShinHer StudyOnline System - Stored XSS

2021-10-1500:00:00
CWE-79
twcert
www.cve.org

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

29.4%

The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title parameter. After logging in with user’s privilege, remote attackers can inject JavaScript and execute stored XSS attacks.

CNA Affected

[
  {
    "product": "ShinHer StudyOnline System",
    "vendor": "ShinHer Information Co., LTD.",
    "versions": [
      {
        "lessThanOrEqual": "2021",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

29.4%

Related for CVELIST:CVE-2021-42329