Persistent cross-site scripting (XSS) in the web interface of Concerto through 2.3.6 allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into the First Name or Last Name parameter upon registration. When a privileged user attempts to delete the account, the XSS payload will be executed.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-05-19T14:06:57

Updated: 2021-05-19T14:06:57

Reserved: 2021-04-30T00:00:00


Link: CVE-2021-31930

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-05-19T15:15:08.850

Modified: 2021-05-25T14:26:14.820


Link: CVE-2021-31930

JSON object: View

cve-icon Redhat Information

No data.

CWE