Cross Site Scripting Vulnerability in Priority Enterprise Management System
CVE-2021-26832
6.1MEDIUM
Key Information:
- Vendor
Priority-software
- Vendor
- CVE Published:
- 14 April 2021
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2021-26832?
A Cross Site Scripting vulnerability exists in the 'Reset Password' page of Priority Enterprise Management System v8.00, allowing attackers to craft malicious URLs that can execute JavaScript in the context of a victim's browser. By directing users to these malicious links, attackers can manipulate user sessions or extract sensitive data. Organizations using this software must ensure timely updates and user awareness to mitigate such risks.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
