CVE-2021-32536

The login page in the MCUsystem does not filter with special characters, which allows remote attackers can inject JavaScript without privilege and thus perform reflected XSS attacks.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-4811-4a160-1.html Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mcusystem:mcusystem:5.5:*:*:*:*:*:*:*

Information

Published : 2021-06-18 10:15

Updated : 2021-06-24 16:01


NVD link : CVE-2021-32536

Mitre link : CVE-2021-32536


JSON object : View

Products Affected

mcusystem

  • mcusystem
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')