← Back to CVE List
CVE-2021-30171
Special characters of ERP POS news page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information.
> MITRE Terms of Use apply – see LICENSE‑MITRE.txt