CVE-2021-28000
Summary
| CVE | CVE-2021-28000 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-19 14:39:00 UTC |
| Updated | 2021-08-23 15:00:00 UTC |
| Description | A persistent cross-site scripting vulnerability was discovered in Local Services Search Engine Management System Project 1.0 which allows remote attackers to execute arbitrary code via crafted payloads entered into the Name and Address fields. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Local Services Search Engine Management System Project | Local Services Search Engine Management System | 1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Local Services Search Engine Management System Project (LSSMES) 1.0 — ‘Person List’ Persistent Cross-Site Scripting (XSS) | by Tushar | Medium | MISC | tusharvaidya16.medium.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.