CVE-2021-45228
14.04.2022, 15:15
An XSS issue was discovered in COINS Construction Cloud 11.12. Due to insufficient neutralization of user input in the description of a task, it is possible to store malicious JavaScript code in the task description. This is later executed when it is reflected back to the user.
Vendor | Product | Version |
---|---|---|
coins-global | coins_construction_cloud | 11.12 |
𝑥
= Vulnerable software versions
References