CVE-2021-31674
02.05.2022, 00:15
Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant.
Vendor | Product | Version |
---|---|---|
cyclos | cyclos | 4.0.0 ≤ 𝑥 ≤ 4.14.7 |
𝑥
= Vulnerable software versions
References