3.5
CVSSv2

CVE-2021-38113

Published: 04/08/2021 Updated: 11/08/2021
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

In addBouquet in js/bqe.js in OpenWebif (aka e2openplugin-OpenWebif) up to and including 1.4.7, inserting JavaScript into the Add Bouquet feature of the Bouquet Editor (i.e., bouqueteditor/api/addbouquet?name=) leads to Stored XSS.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openwebif project openwebif