CVE-2021-37211
09.08.2021, 10:15
The bulletin function of Flygo does not filter special characters while a new announcement is added. Remoter attackers can use the vulnerability with general users credential to inject JavaScript and execute stored XSS attacks.
Vendor | Product | Version |
---|---|---|
larvata | flygo | 𝑥 < 1.91.1 |
𝑥
= Vulnerable software versions