Vulnerability Description
Cross Site Scripting vulnerability found in VICIdial v2.14-610c and v.2.10-415c allows attackers execute arbitrary code via the /agc/vicidial.php, agc/vicidial-greay.php, and /vicidial/KHOMP_admin.php parameters.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vicidial | Vicidial | 2.9-401c |
Related Weaknesses (CWE)
References
- http://vicidial.comProduct
- https://www.vicidial.org/VICIDIALforum/viewtopic.php?f=2&t=41634Vendor Advisory
- http://vicidial.comProduct
- https://www.vicidial.org/VICIDIALforum/viewtopic.php?f=2&t=41634Vendor Advisory
FAQ
What is CVE-2021-35377?
CVE-2021-35377 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross Site Scripting vulnerability found in VICIdial v2.14-610c and v.2.10-415c allows attackers execute arbitrary code via the /agc/vicidial.php, agc/vicidial-greay.php, and /vicidial/KHOMP_admin.php...
How severe is CVE-2021-35377?
CVE-2021-35377 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-35377?
Check the references section above for vendor advisories and patch information. Affected products include: Vicidial Vicidial.