3.5
CVSSv2

CVE-2021-45888

Published: 13/03/2022 Updated: 20/03/2022
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

An issue exists in PONTON X/P Messenger prior to 3.11.2. The navigation tree that is shown on the left side of every page of the web application is vulnerable to XSS: it allows injection of JavaScript into its nodes. Creating such nodes is only possible for users who have the role Configuration Administrator or Administrator.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ponton x\\/p messenger 3.8.0

ponton x\\/p messenger 3.10.0