CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.7. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.
CVE
CVE-2021-32542
Severity
MEDIUM
CVSS
4.7
EPSS
0.68%
Original NVD Description
The parameters of the specific functions in the CTS Web trading system do not filter special characters, which allows unauthenticated attackers can remotely perform reflected XSS and obtain the users’ connection token that triggered the attack.
Related CVEs
Other vulnerabilities affecting the same vendor(s)