Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Enterprise_resource_planning_point_of_sale_system
(Junhetec)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 2 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2021-05-07 | CVE-2021-30170 | Special characters of ERP POS customer profile page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information. | Enterprise_resource_planning_point_of_sale_system | 5.4 | ||
2021-05-07 | CVE-2021-30171 | Special characters of ERP POS news page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information. | Enterprise_resource_planning_point_of_sale_system | 5.4 |