CVE-2021-31583

CVE-2021-31583

Sipwise C5 NGCP CSC through CE_m39.3.1 has multiple authenticated stored and reflected XSS vulnerabilities when input passed via several parameters to several scripts is not properly sanitized before being returned to the user: Stored XSS in callforward/time/set/save (POST tsetname); Reflected XSS in addressbook (GET filter); Stored XSS in addressbook/save (POST firstname, lastname, company); and Reflected XSS in statistics/versions (GET lang).

Source: CVE-2021-31583

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다