Lucene search

K
osvGoogleOSV:CVE-2021-40972
HistoryOct 01, 2021 - 4:15 p.m.

CVE-2021-40972

2021-10-0116:15:07
Google
osv.dev
4
cve-2021-40972
templates
installer
spotweb
remote attackers
web script
html
mail parameter
software

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

50.0%

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the mail parameter.

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

50.0%