CVE-2021-27930
06.07.2021, 12:15
Multiple stored XSS vulnerabilities in IrisNext Edition 9.5.16, which allows an authenticated (or compromised) user to inject malicious JavaScript in folder/file name within the application in order to grab other users sessions or execute malicious code in their browsers (1-click RCE).
Vendor | Product | Version |
---|---|---|
irislink | irisnext | 9.5.16 |
𝑥
= Vulnerable software versions