Jun-He Technology Ltd. ERP POS - Stored XSS-2
Vulnerability Description
Special characters of ERP POS news page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-30171
Credits & Attribution
No credits recorded in the NVD database.
More from Jun-He Technology Ltd.
View All →Affected Vendor
Jun-He Technology Ltd.
View all reports →