384
VMScore

CVE-2021-31537

Published: 11/05/2021 Updated: 19/05/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

SIS SIS-REWE Go prior to 7.7 SP17 allows XSS: rewe/prod/web/index.php (affected parameters are config, version, win, db, pwd, and user) and /rewe/prod/web/rewe_go_check.php (version and all other parameters).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sisinformatik sis-rewe go 7.7

sisinformatik sis-rewe go

Exploits

SIS-REWE GO version 750/12C suffers from multiple cross site scripting vulnerabilities ...

Mailing Lists

SEC Consult Vulnerability Lab Security Advisory < 20210511-0 > ======================================================================= title: Reflected Cross-site Scripting Vulnerabilities product: SIS Informatik - REWE GO vulnerable version: 750/12C fixed version: 77 SP17 CVE number: CVE-2021-3153 ...