CVE-2021-37470

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
25/07/2021
Last modified:
30/07/2021

Description

In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user can add or modify the affected field to inject arbitrary JavaScript.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nchsoftware:webdictate:*:*:*:*:*:*:*:* 2.13 (including)