QSearchQSearch

CVE-2021-42329

5.4 MEDIUM

The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title parameter

Published: 2021-10-15 · Last updated: 2026-06-17

Severity and scoring

CVSS
5.4 MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE
CWE-79

Affected products

VendorProduct
xinheinformationxinhe_teaching_platform_system

Description

The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title parameter. After logging in with user’s privilege, remote attackers can inject JavaScript and execute stored XSS attacks.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2021-42332 The “List View” function of ShinHer StudyOnline System is not under authority control (4.3 MEDIUM)
  • CVE-2021-42331 The “Study Edit” function of ShinHer StudyOnline System does not perform permission control (5.4 MEDIUM)
  • CVE-2021-42330 The “Teacher Edit” function of ShinHer StudyOnline System does not perform authority control (8.8 HIGH)

Same CWE

  • CVE-2026-12425 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access ...
  • CVE-2024-30476 PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager (5.4 MEDIUM)
  • CVE-2026-54198 Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions (7.1 HIGH)
  • CVE-2026-54191 Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions (7.1 HIGH)
  • CVE-2026-39437 Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions (7.1 HIGH)