CVE-2021-45224

CVE-2021-45224

An issue was discovered in COINS Construction Cloud 11.12. In several locations throughout the application, JavaScript code is passed as a URL parameter. Attackers can trivially alter this code to cause malicious behaviour. The application is therefore vulnerable to reflected XSS via malicious URLs.

Source: CVE-2021-45224

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다