← Back to CVE List

CVE-2021-30170

Published: 2021-05-07T10:15Z
Last Modified: 2024-11-21T06:03Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Special characters of ERP POS customer profile page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt