CVE-2021-29267
EUVD-2021-1590529.03.2021, 16:15
Sherlock SherlockIM through 2021-03-29 allows Cross Site Scripting (XSS) by leveraging the api/Files/Attachment URI to attack help-desk staff via the chatbot feature.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| sherlockim | sherlockim | 𝑥 ≤ 2021-03-29 |
𝑥
= Vulnerable software versions