CVE-2021-37211
EUVD-2021-2378509.08.2021, 10:15
The bulletin function of Flygo does not filter special characters while a new announcement is added. Remoter attackers can use the vulnerability with general user’s credential to inject JavaScript and execute stored XSS attacks.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| larvata | flygo | 𝑥 < 1.91.1 |
𝑥
= Vulnerable software versions