Grand Vice info Co. webopac7 - Reflected XSS
CVE-2021-42838

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
15 November 2021

What is CVE-2021-42838?

Grand Vice info Co. webopac7 book search field parameter does not properly restrict the input of special characters, thus unauthenticated attackers can inject JavaScript syntax remotely, and further perform reflective XSS attacks.

Affected Version(s)

webopac7 7.1.20160701

webopac7 1.8.20160701

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.