GHSA-x493-7fm3-mc5qMediumCVSS 6.1
Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote...
🔗 CVE IDs covered (1)
📋 Description
Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2021-31674
- https://tf1t.gitbook.io/mycve/cylos/cyclos-4.14.7-dom-based-cross-site-scripting-in-undefined-enum-cve-2021-31674
- http://cyclos.com
- https://www.exploit-db.com/exploits/50908
- http://packetstormsecurity.com/files/167040/Cyclos-4.14.7-Cross-Site-Scripting.html
- https://github.com/advisories/GHSA-x493-7fm3-mc5q