First published: Fri Feb 11 2022(Updated: )
The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vulnerability could be used to carry out a number of browser-based attacks including browser hijacking or theft of sensitive data.
Credit: cve-coordination@incibe.es cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
TCMAN GIM | =8.0.1 | |
TCMAN GIM | =8.01 |
This vulnerability has been solved by TCMAN in GIM v8.0.1 Release 31734.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-4046.
The title of this vulnerability is 'The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks.'
The severity of CVE-2021-4046 is medium with a CVSS score of 5.4.
The affected software versions are TCMAN GIM v8.0.1 and v8.01.
An attacker can exploit this vulnerability by injecting malicious code through the 'm_txtNom' and 'm_txtCognoms' parameters in TCMAN GIM v8.01.