Cross Site Scripting Vulnerability in Attendance Management System by XYZ Corp
CVE-2021-44598
6.1MEDIUM
Key Information:
- Vendor
- CVE Published:
- 26 December 2021
What is CVE-2021-44598?
The Attendance Management System 1.0 from XYZ Corp is susceptible to a Cross Site Scripting (XSS) vulnerability. This issue arises when the FirstRecord request parameter's value is improperly included in the HTML tag attribute, allowing attackers to exploit this weakness. By employing an XSS-reflected attack, an attacker can manipulate the system, potentially gaining unauthorized access to the admin account and compromising sensitive user information.
