PT-2022-12310 · Coins · Coins Construction Cloud

Jürgen Zöller

·

Published

2022-01-24

·

Updated

2023-10-18

·

CVE-2021-45225

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions COINS Construction Cloud version 11.12
Description The issue is related to improper input neutralization, making it vulnerable to reflected cross-site scripting (XSS) via malicious links. This affects the search window and activity view window.
Recommendations For COINS Construction Cloud version 11.12, update to a version that properly neutralizes input to prevent reflected cross-site scripting (XSS) attacks. As a temporary workaround, consider restricting access to the search window and activity view window to minimize the risk of exploitation. Avoid using malicious links that could trigger the XSS vulnerability until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-45225

Affected Products

Coins Construction Cloud