VYPR
Unrated severityNVD Advisory· Published Apr 14, 2022· Updated Aug 4, 2024

CVE-2021-45227

CVE-2021-45227

Description

An issue was discovered in COINS Construction Cloud 11.12. Due to an inappropriate use of HTML IFRAME elements, the file upload functionality is vulnerable to a persistent Cross-Site Scripting (XSS) attack.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

COINS Construction Cloud 11.12 suffers from persistent XSS via file upload due to improper IFRAME handling, allowing arbitrary script injection.

Vulnerability

The vulnerability is a persistent cross-site scripting (XSS) in COINS Construction Cloud version 11.12. The file upload functionality inappropriately uses HTML IFRAME elements, allowing an attacker to upload a file containing malicious JavaScript that gets executed when other users view the uploaded content. The affected version is 11.12 as tested [1].

Exploitation

An attacker needs to be able to upload files to the system. No special privileges are mentioned; presumably any authenticated user with file upload permissions can exploit this. The attacker uploads a crafted file containing an IFRAME element with malicious script. When other users access the uploaded file, the script executes in their browser context.

Impact

Successful exploitation leads to persistent XSS, meaning the injected script runs each time the malicious file is viewed. The attacker can perform actions on behalf of the victim, steal session cookies, or deface content. The impact is within the web application's security context.

Mitigation

As of the advisory publication (2022-01-13), no fix was available. The manufacturer was notified on 2021-11-02 but no solution date was provided [1]. Users should monitor for updates from COINS. No workaround is mentioned. The vulnerability is not listed in CISA KEV as of this writing.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.