Weintek EasyWeb cMT Cross-site Scripting
CVE-2021-27442

9.4CRITICAL

What is CVE-2021-27442?

The Weintek cMT product line is vulnerable to a cross-site scripting vulnerability, which could allow an unauthenticated remote attacker to inject malicious JavaScript code.

Affected Version(s)

cMT-CTRL01 < 20210302

cMT-FHD < 20210208

cMT-G01/G02 < 20210209

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marcin Dudek from CERT.PL reported these vulnerabilities to CISA.
.