CVE-2021-38710

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
18/08/2021
Last modified:
24/08/2021

Description

Static (Persistent) XSS Vulnerability exists in version 4.3.0 of Yclas when using the install/view/form.php script. An attacker can store XSS in the database through the vulnerable SITE_NAME parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:yclas:yclas:4.3.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools