VulnerabilityModified
CVE-2021-3150
A cross-site scripting (XSS) vulnerability on the Delete Personal Data page in Cryptshare Server before 4.8.0 allows an attacker to inject arbitrary web script or HTML via the user name.
MEDIUM 6.1EPSS 0.63%
Does this matter?
Lower severity and a low EPSS score (0.63%). Track it; it rarely justifies an emergency change on its own.
Description
A cross-site scripting (XSS) vulnerability on the Delete Personal Data page in Cryptshare Server before 4.8.0 allows an attacker to inject arbitrary web script or HTML via the user name. The issue is fixed with the version 4.8.1
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.63% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- cryptshare/cryptshare server
- Source
- cve@mitre.org
References
- https://kc.mcafee.com/corporate/index?page=content&id=SB10356Third Party Advisory
- https://wiki.cryptshare.com/display/CSM/Update+from+v4.7.1+to+v4.8.1Vendor Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10356Third Party Advisory
- https://wiki.cryptshare.com/display/CSM/Update+from+v4.7.1+to+v4.8.1Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.