Persistent XSS Vulnerability in NCH WebDictate v2.13

Persistent XSS Vulnerability in NCH WebDictate v2.13

CVE-2021-37470 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user can add or modify the affected field to inject arbitrary JavaScript.

Learn more about our Web App Pen Testing.