CVE-2021-38709
EUVD-2021-2514716.08.2021, 03:15
In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via the staff_messaging messaging system for XSS.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| compo | composr_cms | 𝑥 < 10.0.38 |
𝑥
= Vulnerable software versions