Weintek EasyWeb cMT Cross-site Scripting
CVE-2021-27442
9.4CRITICAL
What is CVE-2021-27442?
The Weintek cMT product line is vulnerable to a cross-site scripting vulnerability, which could allow an unauthenticated remote attacker to inject malicious JavaScript code.
Affected Version(s)
cMT-CTRL01 < 20210302
cMT-FHD < 20210208
cMT-G01/G02 < 20210209
References
CVSS V3.1
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Marcin Dudek from CERT.PL reported these vulnerabilities to CISA.
