CVE

CVE-2021-27930

CVE-2021-27930

Multiple stored cross-site scripting (XSS) vulnerabilities in IRIS IrisNext 9.5.16 allow remote authenticated users to inject arbitrary web script or HTML via a document or folder name that is mishandled when rendering the contact form or search form.

Source: CVE-2021-27930

Exit mobile version