← Back to CVEs
CVE-2021-4035
LOW3.5
Description
A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of tinymce editor. In order to exploit this vulnerability, the attackers needs an account with enough privileges to view and edit reports.
CVE Details
CVSS v3.1 Score3.5
SeverityLOW
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredHIGH
User InteractionREQUIRED
Published2/11/2022
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
wocu-monitoring:wocu_monitoring
Weaknesses (CWE)
CWE-79CWE-79
References
https://www.incibe.es/en/incibe-cert/notices/aviso/wocu-monitoring-stored-cross-site-scripting-xss(cve-coordination@incibe.es)
https://www.incibe.es/en/incibe-cert/notices/aviso/wocu-monitoring-stored-cross-site-scripting-xss(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.