CVE-2021-3318: XSS
Published Jan 27, 2021
·Updated
attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.
Affected Software
1 affected component
dzzoffice DzzOffice<=2.02.1
Event History
Jan 27, 2021
CVE Published
via MITRE·05:13 PM
Data Sourced
via MITRE·05:13 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2021-3318.
2
What is the title of this vulnerability?
The title of this vulnerability is 'attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.'
3
What is the severity of CVE-2021-3318?
The severity of CVE-2021-3318 is medium with a severity value of 6.1.
4
How can the attacker exploit this vulnerability?
The attacker can exploit this vulnerability by injecting malicious scripts through the 'editorid' parameter in the 'attach/ajax.php' file.
5
Are there any known fixes or patches for this vulnerability?
At the moment, there are no known fixes or patches available for CVE-2021-3318. It is recommended to update to a newer version of DzzOffice when a fix becomes available.