101eip
by Hundredplus
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-32540 | Med | 0.35 | 5.4 | 0.00 | May 28, 2021 | Add announcement function in the 101EIP system does not filter special characters, which allows authenticated users to inject JavaScript and perform a stored XSS attack. | ||
| CVE-2021-32539 | Med | 0.35 | 5.4 | 0.01 | May 28, 2021 | Add event in calendar function in the 101EIP system does not filter special characters in specific fields, which allows remote authenticated users to inject JavaScript and perform a stored XSS attack. |
- risk 0.35cvss 5.4epss 0.00
Add announcement function in the 101EIP system does not filter special characters, which allows authenticated users to inject JavaScript and perform a stored XSS attack.
- risk 0.35cvss 5.4epss 0.01
Add event in calendar function in the 101EIP system does not filter special characters in specific fields, which allows remote authenticated users to inject JavaScript and perform a stored XSS attack.