Cross-site Scripting Vulnerability in Spotweb by Spotweb
CVE-2021-40969
6.1MEDIUM
What is CVE-2021-40969?
A cross-site scripting vulnerability exists in the Spotweb application, specifically in the 'templates/installer/step-004.inc.php' file. This flaw allows remote attackers to inject arbitrary web scripts or HTML through the 'firstname' parameter. Such an injection can lead to unauthorized actions being executed in the context of the user’s browser, potentially compromising sensitive user data and the integrity of the application.
