SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-32536

The login page in the MCUsystem does not filter with special characters, which allows remote attackers can inject JavaScript without privilege and thus perform reflected XSS attacks.

MEDIUM 6.1EPSS 0.79%

Does this matter?

Lower severity and a low EPSS score (0.79%). Track it; it rarely justifies an emergency change on its own.

Description

The login page in the MCUsystem does not filter with special characters, which allows remote attackers can inject JavaScript without privilege and thus perform reflected XSS attacks.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.79% probability · 54th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
mcusystem/mcusystem
Source
twcert@cert.org.tw

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.