Cross Site Scripting Vulnerability in Attendance Management System by XYZ Corp
CVE-2021-44598

6.1MEDIUM

What is CVE-2021-44598?

The Attendance Management System 1.0 from XYZ Corp is susceptible to a Cross Site Scripting (XSS) vulnerability. This issue arises when the FirstRecord request parameter's value is improperly included in the HTML tag attribute, allowing attackers to exploit this weakness. By employing an XSS-reflected attack, an attacker can manipulate the system, potentially gaining unauthorized access to the admin account and compromising sensitive user information.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.