PT-2021-21686 · Nch · Nch Webdictate
Published
2021-07-25
·
Updated
2021-07-30
·
CVE-2021-37470
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
NCH WebDictate version 2.13
Description
The issue concerns a persistent Cross Site Scripting (XSS) flaw in the Recipient Name field. An authenticated user can exploit this by adding or modifying the field to inject arbitrary JavaScript.
Recommendations
For NCH WebDictate version 2.13, consider restricting access to the Recipient Name field until a patch is available to prevent the injection of arbitrary JavaScript.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nch Webdictate