First published: Sun Jul 25 2021(Updated: )
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nchsoftware Ivm Attendant | <=5.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-37451 is medium.
The affected software of CVE-2021-37451 is NCH IVM Attendant v5.12 and earlier.
An attacker can exploit CVE-2021-37451 through Cross Site Scripting (XSS) by manipulating the /msglist?mbx= parameter.
It is recommended to update NCH IVM Attendant to a version higher than 5.12 to mitigate the vulnerability.
You can find more information about CVE-2021-37451 on GitHub and the official NCH IVM Attendant website.