Medium severity5.4NVD Advisory· Published Sep 17, 2021· Updated Jun 17, 2026
CVE-2021-41391
CVE-2021-41391
Description
In Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vulnerable to stored XSS via a name, leading to session hijacking and full account takeover.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:ericsson:enterprise_content_management:18.0:*:*:*:*:*:*:*
- Ericsson/ECMdescription
Patches
Vulnerability mechanics
References
1- the-it-wonders.blogspot.com/2021/09/ericsson-ecm-enterprise-content.htmlnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.