PT-2022-12312 · Unknown · Coins Construction Cloud

Published

2022-04-14

·

Updated

2022-04-21

·

CVE-2021-45227

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions COINS Construction Cloud version 11.12
Description The issue is related to an inappropriate use of HTML IFRAME elements in the file upload functionality, making it vulnerable to a persistent Cross-Site Scripting (XSS) attack. This allows for malicious scripts to be uploaded and executed, potentially leading to unauthorized access or data manipulation.
Recommendations For COINS Construction Cloud version 11.12, consider disabling the file upload functionality until a patch is available to prevent exploitation of the persistent Cross-Site Scripting (XSS) attack. Restrict access to the file upload feature to minimize the risk of malicious script execution.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-45227

Affected Products

Coins Construction Cloud