{"api_version":"1","generated_at":"2026-07-23T23:04:44+00:00","cve":"CVE-2021-42329","urls":{"html":"https://cve.report/CVE-2021-42329","api":"https://cve.report/api/cve/CVE-2021-42329.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-42329","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-42329"},"summary":{"title":"CVE-2021-42329","description":"The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title parameter. After logging in with user’s privilege, remote attackers can inject JavaScript and execute stored XSS attacks.","state":"PUBLIC","assigner":"cve@cert.org.tw","published_at":"2021-10-15 12:15:00","updated_at":"2021-10-20 17:26:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://www.twcert.org.tw/tw/cp-132-5199-61238-1.html","name":"N/A","refsource":"CONFIRM","tags":[],"title":"TWCERT/CC台灣電腦網路危機處理暨協調中心-欣河資訊 欣河教學平台系統 - Stored XSS","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-42329","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-42329","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"42329","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xinheinformation","cpe5":"xinhe_teaching_platform_system","cpe6":"v2021","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"AKA":"TWCERT/CC","ASSIGNER":"cve@cert.org.tw","DATE_PUBLIC":"2021-10-15T11:38:00.000Z","ID":"CVE-2021-42329","STATE":"PUBLIC","TITLE":"ShinHer Information Co., LTD. ShinHer StudyOnline System - Stored XSS"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"ShinHer StudyOnline System","version":{"version_data":[{"version_affected":"<=","version_value":"2021"}]}}]},"vendor_name":"ShinHer Information Co., LTD."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title parameter. After logging in with user’s privilege, remote attackers can inject JavaScript and execute stored XSS attacks."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-79 Cross-site Scripting (XSS)"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://www.twcert.org.tw/tw/cp-132-5199-61238-1.html","name":"https://www.twcert.org.tw/tw/cp-132-5199-61238-1.html"}]},"solution":[{"lang":"eng","value":"Update ShinHer StudyOnline System to version v2021.08.20.01"}],"source":{"advisory":"TVN-202110001","discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2021-10-15 12:15:00","lastModifiedDate":"2021-10-20 17:26:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:xinheinformation:xinhe_teaching_platform_system:v2021:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"42329","Ordinal":"218294","Title":"CVE-2021-42329","CVE":"CVE-2021-42329","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"42329","Ordinal":"1","NoteData":"The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title parameter. After logging in with user’s privilege, remote attackers can inject JavaScript and execute stored XSS attacks.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"42329","Ordinal":"2","NoteData":"2021-10-15","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"42329","Ordinal":"3","NoteData":"2021-10-15","Type":"Other","Title":"Modified"}]}}}