CVE Published: 15/10/2021 |
CVE Updated: 17/09/2024 |
CVE Year: 2021 Source: twcert |
Vendor: ShinHer Information Co., LTD. |
Product: ShinHer StudyOnline System Status : PUBLISHED
CVE-2021-42329 Description
The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title parameter. After logging in with user’s privilege, remote attackers can inject JavaScript and execute stored XSS attacks.
Metrics
CVSS Version: 3.1 |
Base Score: 5.4 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N