AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-32542

MEDIUM · CVSS 4.7 EPSS 0.68%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-05-28 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.7. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.

CVE
CVE-2021-32542
Severity
MEDIUM
CVSS
4.7
EPSS
0.68%

Original NVD Description

The parameters of the specific functions in the CTS Web trading system do not filter special characters, which allows unauthenticated attackers can remotely perform reflected XSS and obtain the users’ connection token that triggered the attack.

Related CVEs

Other vulnerabilities affecting the same vendor(s)