CVE-2021-40637: XSS
OS4ED openSIS 8.0 is affected by cross-site scripting (XSS) in EmailCheckOthers.php. An attacker can inject JavaScript code to get the user's cookie and take over the working session of user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-40637?
CVE-2021-40637 is a vulnerability that affects OS4ED openSIS 8.0 and allows for cross-site scripting (XSS) attacks.
What is the severity of CVE-2021-40637?
CVE-2021-40637 has a severity level of medium with a CVSS score of 6.1.
How does CVE-2021-40637 work?
CVE-2021-40637 allows an attacker to inject JavaScript code through EmailCheckOthers.php in order to obtain the user's cookie and take control of their session.
Which software versions are affected by CVE-2021-40637?
OpenSIS 8.0 by OS4ED is the only affected software version for CVE-2021-40637.
Is there a fix for CVE-2021-40637?
At the moment, there is no official fix available for CVE-2021-40637, but it is recommended to follow the GitHub issue provided for any updates or patches.