First published: Tue May 17 2022(Updated: )
Stored cross-site scripting (XSS) in admin/usermanager.php over IPPlan v4.92b allows remote attackers to inject arbitrary web script or HTML via the userid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ipplan Project Ipplan | =4.92b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42943 is a vulnerability in IPPlan v4.92b that allows remote attackers to inject arbitrary web script or HTML via the userid parameter in admin/usermanager.php.
CVE-2021-42943 has a severity rating of 5.4, which is considered medium.
IPPlan v4.92b is affected by CVE-2021-42943.
Remote attackers can exploit CVE-2021-42943 by injecting arbitrary web script or HTML via the userid parameter in admin/usermanager.php.
A fix for CVE-2021-42943 may be available. Please refer to the official documentation or vendor for a patch or update.