CVE-2021-33849
Summary
| CVE | CVE-2021-33849 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-05 22:15:00 UTC |
| Updated | 2021-10-14 15:19:00 UTC |
| Description | A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website. The attack targets your application's users and not the application itself while using your application as the attack's vehicle. The XSS payload executes whenever the user changes the form values or deletes a created form in Zoho CRM Lead Magnet Version 1.7.2.4. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Zohocorp | Zoho Crm Lead Magnet | 1.7.2.4 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2020-29322 - D-Link Router DIR-880LTelnet Hardcoded Credentials | MISC | cybersecurityworks.com | |
| CVE-2021-33849 - Stored Cross-Site Scripting (XSS) in WordPress Plugin (ZOHO CRM Lead Magnet Version 1.7.2.4) | MISC | cybersecurityworks.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.