Vulnerability Details CVE-2021-35377
Cross Site Scripting vulnerability found in VICIdial v2.14-610c and v.2.10-415c allows attackers execute arbitrary code via the /agc/vicidial.php, agc/vicidial-greay.php, and /vicidial/KHOMP_admin.php parameters.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.6%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2021-35377
-
cpe:2.3:a:vicidial:vicidial:2.10-415c
-
cpe:2.3:a:vicidial:vicidial:2.14-597c
-
cpe:2.3:a:vicidial:vicidial:2.14-610c
-
cpe:2.3:a:vicidial:vicidial:2.9-401c