CVE-2021-40292: XSS
Published Oct 12, 2021
·Updated
A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter.
Affected Software
1 affected component
dzzoffice DzzOffice=2.02.1
Event History
Oct 12, 2021
CVE Published
via MITRE·05:31 PM
Data Sourced
via MITRE·05:31 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-40292?
The severity of CVE-2021-40292 is medium, with a severity value of 5.4.
2
How does the Stored Cross Site Scripting (XSS) vulnerability in DzzOffice 2.02.1 via the settingnew parameter work?
The vulnerability allows an attacker to inject malicious scripts into a web application, which will be executed by other users viewing the affected page.
3
Is DzzOffice 2.02.1 the only affected version?
Yes, DzzOffice version 2.02.1 is the only version affected by this vulnerability.
4
How can I fix the Stored Cross Site Scripting (XSS) vulnerability in DzzOffice 2.02.1?
Update to a patched version of DzzOffice that has addressed the vulnerability.
5
Where can I find more information about CVE-2021-40292?
You can find more information about CVE-2021-40292 in the GitHub issue: https://github.com/zyx0814/dzzoffice/issues/195