SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-33849

A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website.

MEDIUM 5.4EPSS 1.08%

Does this matter?

Lower severity and a low EPSS score (1.08%). Track it; it rarely justifies an emergency change on its own.

Description

A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website. The attack targets your application's users and not the application itself while using your application as the attack's vehicle. The XSS payload executes whenever the user changes the form values or deletes a created form in Zoho CRM Lead Magnet Version 1.7.2.4.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
1.08% probability · 63th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
zohocorp/zoho crm lead magnet
Source
disclose@cybersecurityworks.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.