PT-2022-12312 · Unknown · Coins Construction Cloud
Published
2022-04-14
·
Updated
2022-04-21
·
CVE-2021-45227
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
COINS Construction Cloud version 11.12
Description
The issue is related to an inappropriate use of HTML IFRAME elements in the file upload functionality, making it vulnerable to a persistent Cross-Site Scripting (XSS) attack. This allows for malicious scripts to be uploaded and executed, potentially leading to unauthorized access or data manipulation.
Recommendations
For COINS Construction Cloud version 11.12, consider disabling the file upload functionality until a patch is available to prevent exploitation of the persistent Cross-Site Scripting (XSS) attack. Restrict access to the file upload feature to minimize the risk of malicious script execution.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coins Construction Cloud