MEDIUM
ctrlo lenio contractor.tt cross site scripting
Published Dec 18, 2022
6.1
MEDIUMCVSS 3.1
EPSS 0.40%
Description
A vulnerability was found in ctrlo lenio and classified as problematic. Affected by this issue is some unknown functionality of the file views/contractor.tt. The manipulation of the argument contractor.name leads to cross site scripting. The attack may be launched remotely. The name of the patch is e1646d5cd0a2fbab9eb505196dd2ca1c9e4cdd97. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216212.
Affected products
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-34101 Advisory
- https://github.com/ctrlo/lenio/commit/e1646d5cd0a2fbab9eb505196dd2ca1c9e4cdd97 PatchThird Party Advisory
- https://vuldb.com/?id.216212 Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-34101 | Advisory | |
| https://github.com/ctrlo/lenio/commit/e1646d5cd0a2fbab9eb505196dd2ca1c9e4cdd97 | PatchThird Party Advisory | |
| https://vuldb.com/?id.216212 | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Dec 18, 2022
Updated Apr 15, 2025
Reserved Dec 18, 2022
Link CVE-2021-4255
CISA Vulnrichment
Updated Apr 14, 2025
ENISA EUVD
EUVD-2021-34101 Assigner VulDB
Published Dec 18, 2022
Updated Apr 15, 2025
Exploited since n/a
Link EUVD-2021-34101