Vulnerability Description
Cross Site Scripting (XSS) in the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute javascript on behalf of the victim by sending a malicious URL or directing the victim to a malicious site.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Priority-Software | Priority Enterprise Management System | 8.00 |
Related Weaknesses (CWE)
References
- https://github.com/NagliNagli/CVE-2021-26832Third Party Advisory
- https://github.com/NagliNagli/CVE-2021-26832Third Party Advisory
FAQ
What is CVE-2021-26832?
CVE-2021-26832 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross Site Scripting (XSS) in the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute javascript on behalf of the victim by sending a malicious URL or...
How severe is CVE-2021-26832?
CVE-2021-26832 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26832?
Check the references section above for vendor advisories and patch information. Affected products include: Priority-Software Priority Enterprise Management System.