SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-30113

A blind XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in event name and description fields.

MEDIUM 6.1EPSS 0.95%

Does this matter?

Lower severity and a low EPSS score (0.95%). Track it; it rarely justifies an emergency change on its own.

Description

A blind XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in event name and description fields. An attacker can inject a JavaScript code that will be stored in the page. If any visitor sees the event, then the payload will be executed and sends the victim's information to the attacker website.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.95% probability · 59th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
web-school/enterprise resource planning
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.