CVE-2021-20128: XSS
Published Oct 13, 2021
·Updated
The Profile Name field in the floor plan (Network Menu) page in Draytek VigorConnect 1.6.0-B3 was found to be vulnerable to stored XSS, as user input is not properly sanitized.
Affected Software
1 affected component
DrayTek VigorConnect=1.6.0-beta3
Event History
Oct 13, 2021
CVE Published
via MITRE·03:49 PM
Data Sourced
via MITRE·03:49 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-20128.
2
What is the affected software for this vulnerability?
The affected software for this vulnerability is Draytek VigorConnect 1.6.0-B3.
3
What is the severity level of this vulnerability?
The severity level of this vulnerability is medium.
4
What is the CWE ID associated with this vulnerability?
The CWE ID associated with this vulnerability is CWE-79.
5
Is there a fix available for this vulnerability?
Yes, it is recommended to update to a version that has fixed this vulnerability.