VYPR
Unrated severityNVD Advisory· Published Aug 18, 2021· Updated Aug 4, 2024

CVE-2021-38710

CVE-2021-38710

Description

Static (Persistent) XSS Vulnerability exists in version 4.3.0 of Yclas when using the install/view/form.php script. An attacker can store XSS in the database through the vulnerable SITE_NAME parameter.

Affected products

2
  • Yclas/Yclasdescription
  • Yclas/Yclasllm-create
    Range: = 4.3.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

News mentions

0

No linked articles in our index yet.