Vulnerability Description
Attendance Management System 1.0 is affected by a Cross Site Scripting (XSS) vulnerability. The value of the FirstRecord request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The attacker can access the system, by using the XSS-reflected method, and then can store information by injecting the admin account on this system.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Attendance Management System Project | Attendance Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44598ExploitThird Party Advisory
- https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44598ExploitThird Party Advisory
FAQ
What is CVE-2021-44598?
CVE-2021-44598 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Attendance Management System 1.0 is affected by a Cross Site Scripting (XSS) vulnerability. The value of the FirstRecord request parameter is copied into the value of an HTML tag attribute which is en...
How severe is CVE-2021-44598?
CVE-2021-44598 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-44598?
Check the references section above for vendor advisories and patch information. Affected products include: Attendance Management System Project Attendance Management System.