go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

ShinHer Information Co., LTD. ShinHer StudyOnline System - Stored XSS

TVN ID TVN-202110001
CVE ID CVE-2021-42329
CVSS 5.4 (Medium)
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected Products ShinHer StudyOnline System v2021
Description The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title parameter. After logging in with user’s privilege, remote attackers can inject JavaScript and execute stored XSS attacks.
Solution Update ShinHer StudyOnline System to version v2021.08.20.01
Credit Allen.Liu、Bingo.Huang
Public Date 2021-10-15
Top