TVN ID | TVN-202105002 |
---|---|
CVE ID | CVE-2021-32540 |
CVSS | 5.4 (Medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Affected Products | Hundred Plus 101EIP version RELEASE_200925 |
Description | Add announcement function in the 101EIP system does not filter special characters, which allows authenticated users to inject JavaScript and perform a stored XSS attack. |
Solution | Update 101EIP version to 210426 |
Public Date | 2021-05-28 |