Cross-Site Scripting Vulnerability in Spotweb by Spotweb
CVE-2021-40970

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
1 October 2021

What is CVE-2021-40970?

A cross-site scripting (XSS) vulnerability exists in the Spotweb application within the templates/installer/step-004.inc.php file. This flaw enables remote attackers to execute arbitrary web scripts or inject HTML code through the username parameter, potentially compromising user data and application integrity.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.