PoC Index

CVE-2021-44310

MEDIUM 4.8EPSS 0.6%

An issue was discovered in Firmware Analysis and Comparison Tool v3.2. With administrator privileges, the attacker could perform stored XSS attacks by inserting JavaScript and HTML code in user creation functionality.

CVSS v3.1
4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
0.57% chance of exploitation in the next 30 days, 45th percentile
Published
2022-03-30
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related