PT-2022-12309 · Unknown · Coins Construction Cloud

Jürgen Zöller

·

Published

2022-01-24

·

Updated

2023-10-18

·

CVE-2021-45224

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions COINS Construction Cloud version 11.12
Description An issue was discovered in the application where JavaScript code is passed as a URL parameter in several locations. This allows attackers to alter the code and cause malicious behavior, making the application vulnerable to reflected XSS via malicious URLs.
Recommendations For COINS Construction Cloud version 11.12, consider restricting access to URL parameters that accept JavaScript code to minimize the risk of exploitation. As a temporary workaround, avoid using URLs with JavaScript code until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-45224

Affected Products

Coins Construction Cloud