CyberSec.Space Logo
Back to CVE Browser

CVE-2021-31930

MEDIUM
6.1
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2021-05-19
Last Modified2024-11-21
Data SourcesNVD

Vulnerability Description

Persistent cross-site scripting (XSS) in the web interface of Concerto through 2.3.6 allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into the First Name or Last Name parameter upon registration. When a privileged user attempts to delete the account, the XSS payload will be executed.

Affected Platforms (CPE)

📦
Concerto Signage

Concerto

<= 2.3.6

References & Advisories

Related Vulnerabilities