PoC Index

CVE-2021-37470

MEDIUM 5.4EPSS 0.6%

In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user can add or modify the affected field to inject arbitrary JavaScript.

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
0.58% chance of exploitation in the next 30 days, 46th percentile
Published
2021-07-25
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related