CVE-2021-46355

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
11/02/2022
Last modified:
07/11/2023

Description

OCS Inventory 2.9.1 is affected by Cross Site Scripting (XSS). To exploit the vulnerability, the attacker needs to manipulate the name of some device on your computer, such as a printer, replacing the device name with some malicious code that allows the execution of Stored Cross-site Scripting (XSS).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:factorfx:ocs_inventory:2.9.1:*:*:*:*:*:*:*