← Back to CVE List

CVE-2021-41557

Published: 2021-12-15T07:15Z
Last Modified: 2024-11-21T06:26Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Sofico Miles RIA 2020.2 Build 127964T is affected by Stored Cross Site Scripting (XSS). An attacker with access to a user account of the RIA IT or the Fleet role can create a crafted work order in the damage reports section (or change existing work orders). The XSS payload is in the work order number. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt