Back

MEDIUM

Attendance Management System 1.0 is affected by a Cross Site Scripting (XSS) vulnerability

Published Dec 26, 2021

Description

Attendance Management System 1.0 is affected by a Cross Site Scripting (XSS) vulnerability. The value of the FirstRecord request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The attacker can access the system, by using the XSS-reflected method, and then can store information by injecting the admin account on this system.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 26, 2021
Updated Aug 4, 2024
Reserved Dec 6, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner mitre
Published Dec 26, 2021
Updated Aug 4, 2024
Exploited since n/a
EUVD-2021-31420