TVN ID | TVN-202101003 |
---|---|
CVE ID | CVE-2021-22849 |
CVSS | 4.6(Medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N |
Affected Products | Hyweb HyCMS-J1 version prior to 7.4.3 |
Description | Hyweb HyCMS-J1 backend editing function does not filter special characters. Users after log-in can inject JavaScript syntax to perform a stored XSS (Stored Cross-site scripting) attack. |
Solution | Update Hyweb HyCMS-J1 to the latest version or contact Hyweb Tech. for vulnerability repairment. |
Credit | Robin Tung (CHT) |
Public Date | 2021-01-19 |