First published: Sun Jul 25 2021(Updated: )
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via the Mailbox name (stored).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nchsoftware Ivm Attendant | <=5.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37448 is a vulnerability that allows for Cross Site Scripting (XSS) attacks in NCH IVM Attendant v5.12 and earlier via the Mailbox name (stored).
CVE-2021-37448 has a severity rating of medium with a CVSS score of 5.4.
CVE-2021-37448 affects NCH IVM Attendant v5.12 and earlier by allowing for Cross Site Scripting (XSS) attacks via the Mailbox name (stored).
To fix CVE-2021-37448, it is recommended to update NCH IVM Attendant to a version beyond v5.12.
The CWE for CVE-2021-37448 is CWE-79, which is the code for Improper Neutralization of Input During Web Page Generation (XSS).