First published: Sun Jul 25 2021(Updated: )
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmlist?folder= (reflected).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nchsoftware Ivm Attendant | <=5.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37449 is a Cross Site Scripting (XSS) vulnerability in NCH IVM Attendant v5.12 and earlier.
The severity of CVE-2021-37449 is medium with a severity score of 5.4.
CVE-2021-37449 is an XSS vulnerability that can be exploited via the /ogmlist?folder= parameter, allowing for the injection of malicious scripts.
To fix CVE-2021-37449, it is recommended to update NCH IVM Attendant to version 5.13 or later.
You can find more information about CVE-2021-37449 on the official NCH IVM Attendant website.