CVE-2021-45224

Publication date

2022-01-24 19:58:24

Family

mitre

State

PUBLISHED

Description

An issue was discovered in COINS Construction Cloud 11.12. In several locations throughout the application, JavaScript code is passed as a URL parameter. Attackers can trivially alter this code to cause malicious behaviour. The application is therefore vulnerable to reflected XSS via malicious URLs.